← Files codex-sdlcARCHIVED FILE
SECURITY.md
857 Bytes · Oct 3, 2026 · 06:35 UTC
# Security policy ## Supported version Security fixes are provided for the latest published codex-sdlc version. ## Reporting a vulnerability Use GitHub private vulnerability reporting for `prime-vimihi/codex-sdlc`. Do not open a public issue with exploit details or sensitive repository content. Include the affected version, reproduction steps, impact, and any suggested mitigation. ## Local data boundary codex-sdlc runs inside the selected repository. It writes framework state and command evidence under `.sdlc/`. Evidence can contain command output, paths, and source-derived diagnostics. Redaction applies only to secret environment variables explicitly named in the installed policy. Review evidence before sharing or committing it. The package has no install or postinstall script and does not require a codex-sdlc account or remote service.
SHA-256: 93ca5a388f16c266b23413d84266502ea05c8faa2a935e7e268b19f41d1c5312