| Version | Supported |
|---|---|
main |
✅ Supported |
v0.1.0 |
✅ Supported |
Do not disclose security vulnerabilities publicly. Report privately through a GitHub Security Advisory on this repository.
Include the affected file, a description, reproduction steps, and a suggested fix if possible.
- The approval gate is the security boundary for automation: irreversible actions require explicit human approval.
- Provider credentials are never committed; they are injected at runtime.
- Audit log is append-only by design so post-hoc tampering is detectable.