Skip to content

Security: covibes/zeroshot

SECURITY.md

Security Policy

Supported Versions

Version Supported
latest

Reporting a Vulnerability

If you discover a security vulnerability in zeroshot, please report it responsibly:

  1. Do NOT open a public GitHub issue for security vulnerabilities
  2. Email the maintainers directly at: security@covibes.io
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Any suggested fixes (optional)

Response Timeline

  • Initial response: Within 48 hours
  • Status update: Within 7 days
  • Fix timeline: Depends on severity, typically within 30 days for critical issues

Scope

This policy applies to:

  • The zeroshot CLI tool
  • Agent execution and isolation mechanisms
  • Message bus and ledger components
  • Docker container configurations

Out of Scope

  • Issues in Claude Code CLI itself (report to Anthropic)
  • Issues in dependencies (report to respective maintainers)
  • Social engineering attacks

Thank you for helping keep zeroshot secure!

There aren’t any published security advisories