Skip to content

Security: ismoilovdevml/firerunner

SECURITY.md

Security policy

FireRunner runs untrusted CI code, so isolation bugs matter. Please do not report them in public issues.

Report privately through GitHub security advisories. Describe what an attacker can do and how to reproduce it. You will get an answer within a week.

Fixes go to main and the edge release; the advisory names the first fixed version.

The security model and its known gaps are described in How it works.

There aren't any published security advisories