The Code Reviewer AI Agent project team takes the security of our software, dependencies, and users seriously.
We support the current release version with security patches:
| Version | Supported |
|---|---|
0.1.x |
✅ |
< 0.1.0 |
❌ |
If you discover a security vulnerability in Code Reviewer AI Agent, please do not open a public issue. Instead, report it privately:
- Email: Send detailed vulnerability information to
security@divmora.com. - GitHub Security Advisory: Open a private draft security advisory at github.com/divmora/code-reviewer-ai-agent/security/advisories/new.
Please include:
- A description of the vulnerability and its potential impact.
- Steps to reproduce the issue (proof-of-concept configuration or code snippet).
- Any proposed remediation or patch.
- Initial Acknowledgment: Within 48 hours.
- Vulnerability Assessment & Triage: Within 5 business days.
- Remediation & Advisory Release: Coordinated with the reporter before public disclosure.
-
Token Principle of Least Privilege:
- Use dedicated service accounts or Project Access Tokens.
- For GitLab: require only
apiorread_repository+write_merge_requestsscope. - For GitHub: require only
pull_requests: write,contents: read,statuses: write. - For Bitbucket: require only
pullrequests:write.
-
Self-Hosted TLS / SSL Verification:
- Only use
--skip-tls-verifyon trusted internal private corporate networks with self-signed CAs. - For public or SaaS environments, always ensure valid SSL/TLS certificate verification.
- Only use
-
Read-Only LocalHarness Sandbox Policy:
- The agent runs with
Capabilities.RunCommand = falseand read-only static analysis safety by default, preventing arbitrary command execution during code analysis.
- The agent runs with
-
Secret & Key Masking:
- Always store
CODE_REVIEWER_LITELLM_API_KEY,LITELLM_API_KEY, and VCS tokens as masked/secret environment variables in CI/CD pipelines (e.g. GitLab CI Masked Variables, GitHub Secrets).
- Always store