Skip to content

Security: MythosMachina/COPM

Security

SECURITY.md

Security Policy

Scope

COPM is intended for DEV/LAN usage and should not be directly exposed to the public internet.

Reporting a Vulnerability

Do not open public issues for sensitive vulnerabilities.

Please report security issues privately to project maintainers with:

  • Summary and impact
  • Reproduction steps
  • Suggested remediation (if available)

Private report channel:

Hard Requirements

  • Use strong secrets for all COPM_* environment variables.
  • Never commit secrets or runtime data.
  • Keep host and dependencies updated.

There aren’t any published security advisories