Skip to content

Security: sentientwave/automata

Security

SECURITY.md

Security Policy

Supported Versions

The latest main branch is supported for security fixes.

Reporting a Vulnerability

Please report vulnerabilities privately to:

Include:

  • affected component(s)
  • reproduction steps
  • impact assessment
  • optional mitigation suggestions

We will acknowledge receipt as soon as possible and coordinate remediation and disclosure.

Disclosure Policy

  • Please do not disclose vulnerabilities publicly until a fix is available.
  • We aim for coordinated disclosure after remediation.

Scope

This policy applies to:

  • Automata core runtime
  • Web/API surface
  • Deployment scripts and container packaging

Out-of-scope examples:

  • third-party service outages
  • unsupported local modifications
  • known risks already documented in project docs/license

There aren’t any published security advisories