Skip to content

Security: SquidSec/SquidGate

Security

SECURITY.md

Security policy

Supported versions

Version Supported
v1.x Yes
main Best effort
Older tags No

Reporting a vulnerability

If you find a security issue in SquidGate:

  1. Do not open a public issue for exploitable bugs.
  2. Contact maintainers via squidoffense.com / SquidSec org.
  3. Include: description, impact, repro, suggested fix.

We aim to acknowledge within 72 hours.

Scope

In scope: secret leakage from the action, unsafe handling of untrusted PR content, supply-chain issues in dist/.

Out of scope: LLM false negatives/positives (model quality), third-party provider issues.

Safe harbor

Good-faith research that follows this policy is welcome.

There aren't any published security advisories