Skip to main content
Language: English

Security policy

RC1 planned public routes cover en and zh-Hant-TW; the 41-locale source catalog is private. This normative security policy remains canonical in English.

If the only proposed evidence source contains private history or sensitive operational material that cannot be sanitized, do not harvest or transmit it. Record only a redacted REJECTED_WITH_EVIDENCE rationale.

Supported versions

VersionSupport
Latest published release and immutable Codex buildSupported
Older immutable cache versionsRollback targets; fixes are not backported unless explicitly announced
Unreleased forks or modified cache contentsNot supported

Report a vulnerability

Please use GitHub private vulnerability reporting. Do not open a public issue for a suspected vulnerability.

Include:

Do not include live credentials, signing keys, provider tokens, raw private prompts, or third-party personal data.

Response

The maintainer will acknowledge a usable report, validate its scope, and coordinate remediation and disclosure. No fixed response-time SLA is promised. Unknown or unreconciled outcomes remain fail-closed.

Security boundaries

Better Workflows assumes a trusted local repository, host, and executable toolchain. Node's Permission Model is defense in depth and is not an OS sandbox for malicious code. See the complete security guide.