Skip to content

Security: AnonShell/agam-space

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Thank you for helping improve Agam Space's security! Your contribution makes the project safer for everyone in the community.

Please do NOT report security vulnerabilities through public GitHub issues.

Instead, report them privately via email to: security.agamspace@proton.me

What to Include

To help us understand and address the issue effectively:

  • Type of vulnerability
  • Full paths of source file(s) related to the vulnerability
  • Location of the affected source code (tag/branch/commit or direct URL)
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if possible)
  • Impact of the issue, including how an attacker might exploit it

The more detail you provide, the faster we can validate and fix the issue.

Disclosure Policy

When we receive a security bug report:

  1. We'll confirm the problem and determine affected versions
  2. Audit code to find any similar problems
  3. Prepare fixes for all supported versions
  4. Release patched versions and publicly acknowledge your contribution (unless you prefer to remain anonymous)

We appreciate your patience as we work to address security issues responsibly.

Security Best Practices for Users

  • Always use the latest stable version
  • Use strong, unique passwords for your master password
  • Enable WebAuthn for additional security
  • Keep your recovery key in a safe place
  • Review trusted devices regularly
  • Use HTTPS in production
  • Follow the deployment security guide in documentation

There aren’t any published security advisories