RepoMedic is intended for local or trusted-network operation. Do not expose the API, dashboard, MCP endpoint, worker, database, or collectors directly to the public internet.
RepoMedic is currently pre-1.0. Security fixes target the default branch unless a maintained release branch is announced.
Please use GitHub private vulnerability reporting or a private security advisory when available. If that is not available, contact the repository owner privately before publishing details.
Do not include real secrets, private repository contents, customer data, or production incident payloads in public issues.
- RepoMedic creates draft PRs only.
- RepoMedic does not auto-merge.
- RepoMedic does not mutate default branches.
- RepoMedic does not deploy or change production systems.
- Repository allowlists, path allowlists, verification commands, and draft PR policy checks must stay enabled for remediation workflows.