| Version | Status |
|---|---|
| Current npm release | Supported |
main |
Unreleased source; security reports are accepted |
| Older releases | Unsupported |
Operon CLI communicates with Operon's live Agent Runtime inside Obsidian. The CLI does not maintain a second task database, but it can read vault-derived data and submit reviewed mutation plans. Please treat transport, local storage, vault identity, authorization, plan recovery, and package integrity issues as security-sensitive.
Use GitHub private vulnerability reporting. Do not open a public issue for a suspected vulnerability.
Include the affected Operon CLI, Operon, Obsidian, Node.js, and operating-system versions; the security boundary involved; a minimal reproduction; and the expected impact. Redact task content, vault paths, request payloads, authentication material, consent records, plan files, and recovery-store contents.
If private reporting is temporarily unavailable, wait for the repository security channel to be restored instead of publishing sensitive details. There is no guaranteed response-time SLA, but valid reports will be reviewed and coordinated before public disclosure.
- Public support questions without a security impact
- Vulnerabilities in unsupported Operon CLI releases
- Reports that require publishing real vault contents or credentials
- Social engineering, denial-of-service testing, or destructive testing
Ordinary bugs and platform feedback can use the public issue tracker after all sensitive data has been removed.