Skip to content

Security: pcvantol/forge

Security

SECURITY.md

Forge Security Policy

Reporting a vulnerability

Do not open a public issue for suspected vulnerabilities, leaked credentials, private URLs, exploit details, raw prompts, runtime receipts, or sensitive logs. Use GitHub private vulnerability reporting when available, or contact the repository owner privately.

Include the affected commit, component, impact, and safe reproduction details. Redact credentials, tokens, private repository data, host diagnostics, and personal data.

Scope

Forge source, workflows, repository contracts, and documentation that can affect repository or engineering governance are in scope. Execution Hosts, their runtime services, and peer products are separate systems; report a cross-boundary issue with the affected components identified.

Safe research

Do not access or modify data you do not own, disrupt services, or publish a vulnerability before a fix or mitigation is available.

There aren't any published security advisories