Skip to content

Security: millsydotdev/CEO-in-a-Box

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, use GitHub's private vulnerability reporting feature at:

https://github.com/millsydotdev/CEO-in-a-Box/security/advisories

You should receive a response within 48 hours. If you don't, please follow up via the same channel.

What to Report

  • Unauthorised access to user data
  • Remote code execution in the plugin runtime
  • Privilege escalation via organisational entities
  • Exposure of secrets, tokens, or credentials
  • Code injection in engine evaluation paths

Supported Versions

Version Supported
Latest npm release
Development builds ⚠️ (best effort)

Process

  1. You submit a private vulnerability report
  2. We acknowledge receipt within 48 hours
  3. We investigate and develop a fix
  4. We release a patched version
  5. We disclose the vulnerability after the fix is available

Preferred Languages

We prefer all communications in English.

There aren't any published security advisories