Mozaiks is pre-launch software (see AGENTS.md). We still take security reports seriously and ask that you report vulnerabilities privately so they can be assessed before any public disclosure.
Please use GitHub's private vulnerability reporting for this repository instead of opening a public issue or pull request:
- Go to the Security tab.
- Select Report a vulnerability.
- Describe the issue, including affected version/commit, reproduction steps, and potential impact.
This opens a private advisory visible only to you and the repository maintainers, who will respond and coordinate a fix and disclosure timeline with you.
Do not include exploit details, credentials, or other sensitive information in a public GitHub issue, discussion, or pull request.
This project is pre-1.0 and does not yet maintain long-term-supported
release branches. Security fixes are applied to the latest release on
main. If you are running an older version, please upgrade before or
alongside reporting an issue.
This policy covers the mozaiks OSS repository (runtime, platform, Studio,
CLI, and factory workflows). It does not cover privately hosted products
built on top of Mozaiks; report issues in those products to their own
maintainers.