Skip to content

Security: robch/cycod

Security

SECURITY.md

Security Policy

Supported Versions

Use this section to tell people about which versions of your project are currently being supported with security updates.

Version Supported
1.0.x

Reporting a Vulnerability

We take the security of CycoD seriously. If you believe you've found a security vulnerability, please follow these steps:

  1. Do not disclose the vulnerability publicly
  2. Email the details to [email protected] (replace with actual contact)
    • Provide a detailed description of the vulnerability
    • Include steps to reproduce the issue
    • Mention the version of the software where you found the vulnerability
    • If possible, include suggestions for addressing the vulnerability

What to expect

  • You will receive an acknowledgment of your report within 48 hours
  • We will investigate and work to verify the vulnerability
  • We will keep you informed about our progress in addressing the vulnerability
  • Once the vulnerability is fixed, we will publicly acknowledge your contribution (unless you prefer to remain anonymous)

Best Practices for Users

To ensure the security of your CycoD deployment:

  1. Always use the latest version of the software
  2. Be careful about the system commands that you allow the AI assistant to execute
  3. Regularly review and purge chat histories that may contain sensitive information
  4. Use appropriate authentication and authorization mechanisms when deploying in shared environments
  5. Be cautious about sharing API keys or sensitive environment variables

Thank you for helping keep CycoD and its users secure!

There aren’t any published security advisories