Skip to content

Security: opertus-systems/provenclaw

Security

SECURITY.md

Security Policy

Supported Versions

This repository is currently in active Phase 0.5 development. The main branch is the supported branch for security fixes.

Reporting a Vulnerability

  1. Do not open a public issue for suspected vulnerabilities.
  2. Use GitHub's private vulnerability reporting for this repository: Security Advisories.
  3. Include clear reproduction steps, impact, affected paths, and any proof-of-concept artifacts.

Response Targets

  1. Initial acknowledgement: within 2 business days.
  2. Triage and severity classification: within 5 business days.
  3. Remediation or mitigation plan: as soon as triage is complete.

Disclosure Policy

  1. We follow coordinated disclosure.
  2. Public disclosure happens only after a fix or acceptable mitigation is available.
  3. Security regressions can block releases.

Scope Notes

  1. Provenance and policy bypasses are considered high severity.
  2. Receipt or audit-chain tampering is considered high severity.
  3. Secret material exposure outside approved boundaries is considered high severity.

There aren’t any published security advisories