Skip to content

Security: 888newstep/novel_agent

Security

SECURITY.md

Security Policy

Supported Versions

Security fixes are applied to the latest maintained state of the master branch unless stated otherwise.

Reporting A Vulnerability

Please do not disclose security issues publicly before review.

Preferred process:

  1. Use GitHub Security Advisories / private reporting if available.
  2. If private reporting is unavailable, open a limited issue without exploit details and request a private follow-up channel.
  3. Include impact, reproduction steps, affected area, and any mitigation ideas.

We will review the report, validate impact, and coordinate a fix before public disclosure.

Dependency Security

The dependency version baseline and upgrade procedure are documented in docs/DEPENDENCY_SECURITY.md. Pull requests also run automated dependency review through GitHub Actions.

There aren't any published security advisories