Skip to content

Security: schema-sandbox/Schema-Sandbox

Security

SECURITY.md

Security Policy

This repository publishes public methodology drafts, reference patterns, schemas, and examples for Schema Sandbox.

Supported scope

Security reports are welcome for:

  • Dangerous or misleading permission-scope examples
  • Unsafe manifest examples
  • JSON Schema mistakes that could encourage unsafe implementations
  • Documentation that may cause incorrect assumptions about production safety

Out of scope

This repository does not provide a production runtime, hosted service, certification service, or official industrial adapter. Vulnerabilities in independent implementations should be reported to their maintainers.

Reporting

Open a GitHub issue for documentation or example-safety concerns. If a report involves sensitive information, contact the maintainers privately through the contact channel listed on SchemaSandbox.com.

Disclaimer

The public methodology is not a production security guarantee. Production use requires independent threat modeling, implementation review, testing, compliance review, and incident-response planning.

There aren't any published security advisories