Skip to content

Security: pcvantol/forge-platform

SECURITY.md

Security policy

Forge Platform accepts security reports through GitHub private vulnerability reporting where available, or via the repository owner's GitHub security contact. Do not include secrets, unredacted credentials, or unpublished artifact locations in public issues.

The future installer accepts only trusted published artifacts, verifies digests and supported signature/provenance evidence, uses least privilege, registers services explicitly, and never relies on localhost trust bypasses. Local components use real consumer credentials.

There aren't any published security advisories