Skip to content

Security: agledger-ai/cli

SECURITY.md

Security Policy

This policy covers the published AGLedger packages. It follows the AGLedger Coordinated Vulnerability Disclosure Policy, published at https://agledger.ai/security/#vulnerability-disclosure, which sets out the scope, the safe harbor for good-faith research, and the disclosure timeline. Where this file and that policy differ, the policy governs.

Reporting a Vulnerability

Report a vulnerability privately, through either channel. Do not open a public issue.

  • GitHub: use the "Report a vulnerability" button on this repository's Security tab for private, coordinated disclosure.
  • Email: security@agledger.ai

Please include the affected package and version, a description of the vulnerability and its impact, reproduction steps or a minimal proof of concept, and a suggested fix if you have one. If your report contains sensitive detail, say so in your first email without including the detail, and we will agree an encrypted channel with you before you send it. We do not currently publish a PGP key.

We aim to acknowledge receipt promptly and to provide an initial assessment as soon as practicable.

Supported Versions

Security fixes target the current published release of each package. Reports against earlier releases are welcome and are triaged on a best-effort basis, and earlier releases are patched at our discretion.

Disclosure

We follow a 90-day coordinated disclosure window: please do not disclose publicly before the earlier of a fix being available or 90 days after your report. For a vulnerability under active exploitation we move faster and coordinate an accelerated timeline with you. We are happy to coordinate CVE assignment and joint disclosure, and with your permission we credit you in the advisory. AGLedger does not currently operate a paid bug-bounty program.

There aren't any published security advisories