Security fixes are considered for the current main branch and for the latest
tagged Alpha (0.1.0-alpha.2). Older Alpha tags are not supported. The
published CLI artifacts are the GitHub Release tarball, the Homebrew
formula that installs that tarball, and the packable simbroker npm
package, and the signed, notarized operator app zip
Simulator-Broker-0.1.0-alpha.2.zip.
Use GitHub Security Advisories for private reports when available. If that is
not available, email support@51code.tw with a subject that starts with
Security: simulator-broker. Do not open a public GitHub issue for
vulnerability reports.
Do not include live credentials, private machine paths, private task links, or third-party customer data in public issues, pull requests, logs, or examples.
Useful private report details include:
- affected command, script, or app surface
- exact version or commit
- reproduction steps using synthetic data
- observed impact
- any safe, redacted logs