1.1 KiB
1.1 KiB
Security Policy (DRAFT stub — see oss/overlay/SECURITY.md)
The authoritative security policy is oss/overlay/SECURITY.md,
which ships publicly as SECURITY.md. It covers:
- Supported versions (latest release +
main). - Private vulnerability reporting (no public issues for undisclosed vulns; use the host's private reporting feature or contact the owner; 7-day ack).
- Deployment baseline (localhost until OAuth, TLS reverse proxy,
safety.bash_sandbox: always, secret hygiene,/metricsrestriction, tool/integration review).
No separate top-level SECURITY.md is needed. Delete this draft after confirming
the overlay policy.