Skip to content

Security: mecemis/repo-medic

Security

SECURITY.md

Security Policy

RepoMedic is intended for local or trusted-network operation. Do not expose the API, dashboard, MCP endpoint, worker, database, or collectors directly to the public internet.

Supported Versions

RepoMedic is currently pre-1.0. Security fixes target the default branch unless a maintained release branch is announced.

Reporting A Vulnerability

Please use GitHub private vulnerability reporting or a private security advisory when available. If that is not available, contact the repository owner privately before publishing details.

Do not include real secrets, private repository contents, customer data, or production incident payloads in public issues.

Safety Boundaries

  • RepoMedic creates draft PRs only.
  • RepoMedic does not auto-merge.
  • RepoMedic does not mutate default branches.
  • RepoMedic does not deploy or change production systems.
  • Repository allowlists, path allowlists, verification commands, and draft PR policy checks must stay enabled for remediation workflows.

There aren't any published security advisories