Skip to content

Security: Epichlo/TokenDamper

Security

SECURITY.md

Security Policy

Reporting Vulnerabilities

If you discover a security issue in TokenDamper, report it privately to the project maintainers instead of opening a public issue.

Include as much detail as possible, including:

  • affected version
  • description of the issue
  • reproduction steps
  • expected impact
  • any relevant logs or fixtures

Supported Versions

Security support applies to released, maintained versions of TokenDamper.

This repository is currently in the pre-release stage, so there are no stable security-supported versions yet.

Security Philosophy

TokenDamper is designed to optimize context safely and predictably.

Security principles:

  • prefer deterministic behavior
  • avoid hidden network dependencies in the core path
  • keep fallback explicit
  • minimize the trust surface
  • keep benchmark and runtime paths separated

Responsible Disclosure

Please allow time for the maintainers to investigate and respond before public disclosure.

The preferred process is:

  1. Report privately
  2. Wait for acknowledgment
  3. Collaborate on a fix
  4. Disclose publicly once a fix is available or a disclosure timeline is agreed

There aren't any published security advisories