Skip to content

Security: seankoji-com/opencode-session-cycler

SECURITY.md

Security policy

Reporting a vulnerability

Do not open a public issue with vulnerability details, credentials, personal data, private hostnames, or private logs.

Use the affected repository's Security tab and select Report a vulnerability when that option is available. This creates a private report for the repository maintainers.

If private vulnerability reporting is unavailable, open a minimal public issue that asks a maintainer to establish a private channel. Include no exploit steps, secret values, or sensitive evidence in that issue.

Scope

This policy covers repositories in the seankoji-com organization. Report the affected repository and version, the impact, and the smallest safe reproduction you can provide privately.

Response

Maintainers will acknowledge valid reports, assess impact, coordinate a fix, and publish an advisory when public disclosure is appropriate. Do not test against systems or data you do not own or have permission to access.

There aren't any published security advisories