Skip to content

Security: tytsxai/social-copilot

Security

SECURITY.md

Security Policy

Supported Versions

Security fixes are provided for the latest main branch and the latest release tag.

Reporting a Vulnerability

Please do not disclose security issues in public Issues.

Use one of the following channels:

When reporting, include:

  1. Affected version / commit SHA
  2. Reproduction steps or PoC
  3. Impact scope and potential abuse path
  4. Suggested mitigation (if any)

Response SLA (Target)

  • Initial acknowledgement: within 72 hours
  • Triage status update: within 7 days
  • Fix ETA communication: as soon as impact is confirmed

Disclosure

After a fix is prepared and users have a reasonable upgrade window, we will publish:

  • A changelog entry with impact summary
  • Recommended upgrade/remediation steps

Security Baseline for Contributors

  • Never commit API keys, tokens, or user data
  • Keep logs and diagnostics free of secrets and raw message content
  • Prefer minimal permissions and least-privilege changes
  • Add/adjust tests for security-critical paths (sanitization, validation, fallback)

There aren’t any published security advisories