Skip to content

Latest commit

 

History

History
45 lines (29 loc) · 1.49 KB

File metadata and controls

45 lines (29 loc) · 1.49 KB

Security Policy

Supported Versions

This is a fork of gstack with opencode support. Security patches are tracked against the upstream release version.

Version Supported
1.39.x Yes
< 1.39 No

Reporting a Vulnerability

If you discover a security vulnerability in gstack-opencodeai, please report it privately.

Do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Instead, report via email to the repository maintainer. For this fork, please open a security advisory on GitHub:

  1. Go to https://github.com/Acharnite/gstack-opencodeai/security/advisories
  2. Click "New draft security advisory"
  3. Fill in the details

You should receive a response within 48 hours. If you don't, please follow up.

What to include

  • A clear description of the vulnerability
  • Steps to reproduce (proof of concept preferred over theory)
  • Affected versions
  • Any potential mitigations you've identified

Scope

This security policy covers the gstack-opencodeai fork. Vulnerabilities in the upstream gstack project should be reported there directly.

Process

  1. You report the vulnerability
  2. We acknowledge receipt within 48 hours
  3. We assess and prepare a fix
  4. We release a patched version and notify you
  5. You confirm the fix resolves the issue

We follow coordinated disclosure: public details are released after the fix is available.