Skip to content

Security: whjvenyl/opencode-damage-control

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in opencode-damage-control, please report it responsibly.

Do not open a public issue.

Instead, use GitHub Security Advisories to report the vulnerability privately.

What to include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response timeline

  • Acknowledgment: within 3 business days
  • Initial assessment: within 7 business days
  • Fix or mitigation: as soon as possible, depending on severity

Supported Versions

Version Supported
Latest Yes

Scope

This is a defense-in-depth plugin. It reduces risk but does not guarantee prevention of all dangerous operations. See Limitations for known constraints.

There aren’t any published security advisories