Skip to content

Security: eggp-dev/conn

SECURITY.md

Security policy / 보안 정책

Supported versions

Conn is a preview. Security fixes target the latest development version and latest preview release; older previews have no backport guarantee.

Conn coordinates trusted humans and agent harnesses. It is not a sandbox and cannot contain a hostile agent or same-user process. Read the trust model and data handling before using it with sensitive projects.

Reporting

Use GitHub private vulnerability reporting if available. If the repository has not enabled it yet, open an issue titled Private security contact requested, containing only a contact request. Do not put exploit instructions, credentials, audit logs or sensitive terminal content in a public issue. A response time is not guaranteed for this early community project.

Reports are most useful with the affected version, OS, profile, minimal reproduction and expected trust boundary. Ordinary UX bugs belong in the issue tracker.

한국어

Conn은 프리뷰 단계이며 최신 개발 버전과 최신 프리뷰 릴리스를 대상으로 보안 수정을 제공합니다. 이전 버전의 백포트는 보장하지 않습니다.

Conn은 신뢰하는 사용자와 에이전트의 협업을 돕는 도구입니다. 악의적인 에이전트나 같은 사용자 권한의 프로세스를 격리하는 샌드박스가 아닙니다. 신뢰 모델과 저장 데이터를 먼저 확인하세요.

가능하면 GitHub 비공개 보안 제보를 이용하세요. 기능이 아직 꺼져 있으면 Private security contact requested 제목으로 연락 방법만 요청하는 이슈를 작성하세요. 공격 방법, 자격 증명, 감사 로그, 민감한 터미널 내용을 공개 이슈에 붙이지 마세요. 초기 커뮤니티 프로젝트로 응답 시간을 보장하지 않습니다.

There aren't any published security advisories