Skip to content

Security: SafetyMP/FidusGate

.github/SECURITY.md

Security Policy

Supported Versions

Only the latest active release on main is supported for security updates:

Version Supported
v1.0.x ✅ Yes
< v1.0 ❌ No

Reporting a Vulnerability

FidusGate takes repository governance and AI sandbox containment security very seriously. If you discover a vulnerability, access-control bypass (e.g. in the Cedar policy logic), container jailbreak (e.g. escaping the gVisor sandbox), or a prompt-injection vulnerability:

  1. Do not open a public GitHub issue.
  2. Report privately via GitHub Security Advisories (preferred).
  3. If that link returns 404, ask a repo admin to enable Settings → Code security → Privately report a security vulnerability, then retry.
  4. Do not email security@fidusgate.io — that domain currently has no public DNS/MX and reports will bounce.
  5. Include detailed steps, sample payloads, and configurations to reproduce where safe.
  6. We aim to acknowledge within 72 hours and coordinate patches under a 90-day responsible disclosure window before publishing details.

Thank you for helping keep FidusGate secure!

Learn more about advisories related to SafetyMP/FidusGate in the GitHub Advisory Database