Skip to content

Security: fiveonecode/simulator-broker

SECURITY.md

Security Policy

Supported Versions

Security fixes are considered for the current main branch and for the latest tagged Alpha (0.1.0-alpha.2). Older Alpha tags are not supported. The published CLI artifacts are the GitHub Release tarball, the Homebrew formula that installs that tarball, and the packable simbroker npm package, and the signed, notarized operator app zip Simulator-Broker-0.1.0-alpha.2.zip.

Reporting A Vulnerability

Use GitHub Security Advisories for private reports when available. If that is not available, email support@51code.tw with a subject that starts with Security: simulator-broker. Do not open a public GitHub issue for vulnerability reports.

Do not include live credentials, private machine paths, private task links, or third-party customer data in public issues, pull requests, logs, or examples.

Useful private report details include:

  • affected command, script, or app surface
  • exact version or commit
  • reproduction steps using synthetic data
  • observed impact
  • any safe, redacted logs

There aren't any published security advisories