Swarm DAO is pre-1.0 software. Security fixes are applied to the latest published release on main.
If you discover a security vulnerability, please report it responsibly:
- Do not open a public GitHub issue.
- Open a private security advisory at https://github.com/guyghost/swarm-dao/security/advisories/new (GitHub "Report a vulnerability").
- Include a clear description, steps to reproduce, and the potential impact.
You will receive an acknowledgement within 7 days. Please allow reasonable time for a fix to be developed and published before any public disclosure.
This policy covers the packages published from this repository:
@guyghost/swarm-dao-core@guyghost/swarm-dao-pi-adapter@guyghost/swarm-dao-opencode-adapter@guyghost/swarm-dao-cli
It does not cover the host coding agents (Pi, OpenCode) themselves — report those to their respective maintainers.