Security fixes are provided for the latest tagged SGRX release.
Report vulnerabilities privately through the repository's GitHub Security Advisories page by selecting Report a vulnerability. Do not include secrets, exploit details, or sensitive source in a public issue.
Include the affected SGRX version, operating system, reproduction steps, impact, and any suggested mitigation. You should receive an acknowledgement within seven days. A coordinated disclosure date will be agreed after the issue is confirmed.
If private vulnerability reporting is temporarily unavailable, open a public issue containing only a request for a private security contact. Do not disclose the vulnerability itself in that issue.
Reports about SGRX orchestration, isolation, provenance, redaction, or command execution are in scope. Vulnerabilities in OpenSrc, Graphify, GitNexus, Git, Node.js, Python, or a researched repository should be reported to their respective maintainers unless SGRX makes the issue exploitable through its own behavior.