Skip to content

Security: gordonlu/deeplossless

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security issue, privacy issue, or sensitive data exposure related to deeplossless, please report it privately.

Please include:

  • a description of the issue
  • reproduction steps if available
  • affected environment/version
  • potential impact
  • relevant logs or traces (redacted if needed)

Contact:

ebgchina+deeplossless@gmail.com

Please do not publicly disclose security vulnerabilities before they have been reviewed.


Response Expectations

This is an early-stage project, but we will try to:

  • acknowledge reports within a few days
  • investigate responsibly
  • coordinate fixes and disclosure when appropriate

Sensitive Data Notice

deeplossless may capture or replay execution traces, tool calls, logs, or session data.

Users should avoid sharing:

  • credentials
  • API keys
  • tokens
  • private repositories
  • personal information
  • confidential execution traces

Please redact sensitive information before sharing traces publicly in issues or discussions.

There aren't any published security advisories