ArchitectOS takes security seriously.
As an open-source engineering intelligence platform, ArchitectOS aims to follow responsible security practices and encourages the community to report potential vulnerabilities.
During the early development phase, security fixes will be provided for the latest available release.
As the project matures, supported versions will be documented here.
If you discover a potential security vulnerability:
Please do not create a public GitHub issue.
Instead, report the issue privately through the project maintainers.
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested remediation if available
After receiving a security report:
- The issue will be reviewed.
- The impact will be assessed.
- A fix will be developed when appropriate.
- A security advisory may be published after remediation.
ArchitectOS aims to follow these principles:
- Secure development practices
- Responsible disclosure
- Transparent communication
- Minimal data collection
- Safe handling of analyzed source code
Future versions may include:
- Automated dependency scanning
- Security workflows
- Supply chain protection
- Signed releases