Skip to content

Security: yanpenalva/context-spec-develop

Security

SECURITY.md

Security Policy

Do not publish suspected vulnerabilities, credentials, personal data or active incident details in issues, pull requests or example work items.

Report a suspected vulnerability through the repository's private security channel. If the adopting project has no channel, its security owner must define one in .context/project/security.md before production use.

Security work may use the Support incident or hotfix workflow, but public artifacts should contain only the minimum information needed for coordination. Rotate exposed credentials immediately and record evidence without copying the secret.

There aren't any published security advisories