Skip to content

Security: lagrangee/coros-codex-mcp-bridge

Security

SECURITY.md

Security Policy

Supported versions

Only the latest commit on the default branch is treated as supported.

Reporting a vulnerability

Please use GitHub's private vulnerability reporting or a private security advisory for this repository instead of opening a public issue:

https://github.com/lagrangee/coros-codex-mcp-bridge/security/advisories/new

Do not include passwords, OAuth codes, access tokens, refresh tokens, or private sport data in a report. If private reporting is unavailable, contact the repository owner through their GitHub profile and share only the minimum reproducible details.

Credential handling

The bridge is designed to read the official COROS CLI token cache locally. Keep that cache outside the repository, restrict it to the owning user, and rotate/re-authorize it if it may have been exposed.

There aren't any published security advisories