Skip to content

Security: caty-ai/errmeter

Security

SECURITY.md

Security policy

Supported versions

Security fixes are supported for 1.x. Use the latest available 1.x release.

Report privately

Use this repository's GitHub Security Advisories to report a vulnerability privately. Do not disclose credentials or exploit details in a public issue.

Include the affected version, operating system, reproduction steps, and expected versus actual behavior. Use synthetic examples with secrets removed.

In scope

  • Redaction of event details, logs, and repair output.
  • The inbox-only token boundary and dispatch environment.
  • Spool and secret-file permissions.
  • The host-hook installer, backups, and restore behavior.

Maintainers will acknowledge reports as availability allows, investigate them, and coordinate remediation and disclosure with the reporter. Response and fix times depend on severity and maintainer availability; there is no guaranteed response window.

There aren't any published security advisories