Skip to content

Security: 7GMA/caldera

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Email security reports to: security@caldera.dev (or open a GitHub private security advisory).

Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact

We will acknowledge within 48 hours and aim to release a fix within 90 days.

Scope

  • Token encryption bypass
  • Authentication / authorization bypass
  • Webhook HMAC verification bypass
  • Credential exposure in logs or API responses

There aren't any published security advisories