Skip to content

Security: giosakti/duragent

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.4.x Yes
< 0.4 No

Reporting a Vulnerability

If you discover a security vulnerability in Duragent, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

Instead:

  1. Email the maintainer directly or use GitHub's private vulnerability reporting
  2. Include a description of the vulnerability, steps to reproduce, and any potential impact
  3. Allow reasonable time for a fix before public disclosure

What to Expect

  • Acknowledgment within 48 hours of your report
  • Status update within 7 days with an assessment and expected timeline
  • Fix and disclosure coordinated with you before public announcement

Scope

This policy applies to the Duragent core runtime and first-party plugins (e.g. duragent-gateway-discord, duragent-gateway-telegram). Third-party plugins are the responsibility of their respective maintainers.

Disclosure Policy

We follow coordinated disclosure. Once a fix is available, we will:

  1. Release a patched version
  2. Publish a security advisory on GitHub
  3. Credit the reporter (unless they prefer anonymity)

There aren’t any published security advisories