Skip to content

Security: jkelly-dev1/agentic-review-gate

SECURITY.md

Security Policy

Reporting a Vulnerability

Please report suspected vulnerabilities privately, not through public issues or pull requests.

Preferred channel: use GitHub's private vulnerability reporting for this repository (the "Report a vulnerability" button on the Security tab). It opens a private advisory visible only to the maintainer.

Aim is to acknowledge a report within 5 business days and to share a resolution or mitigation plan within 30 days. Timelines may vary, as this is maintained in personal time.

Please include enough detail to reproduce the issue: the affected file or endpoint, the version or commit, steps to reproduce, and the impact you observed.

Supported Versions

This is a personal learning and portfolio project. Only the latest commit on the main branch is supported; there are no maintained release branches or backports.

Scope

These are self-contained demo projects, not production services. Provider credentials are supplied by the operator at runtime and are never committed to the repository. Limitations that the README documents as deliberate, out-of-scope seams are noted but may not be actioned.

There aren't any published security advisories