Security Policy

Security Policy

Supported Versions

| Version | Supported |

| ------- | --------- |

| 0.x (latest) | ✅ |

| < 0.x | ❌ |

Reporting a Vulnerability

Do NOT report security vulnerabilities through public GitHub issues.

Instead, please report them via:

What to Include

  1. Description of the vulnerability
  2. Steps to reproduce (if applicable)
  3. Impact — what could an attacker do?
  4. Affected versions
  5. Suggested fix (if you have one)

Response Timeline

StageTarget
AcknowledgmentWithin 24 hours
Initial assessmentWithin 72 hours
Fix or mitigationWithin 7 days (critical), 30 days (non-critical)
Public disclosureAfter fix is released

Disclosure Policy

  • We follow coordinated disclosure
  • We ask that you give us reasonable time to fix the issue before public disclosure
  • We will credit you in the security advisory (unless you prefer to remain anonymous)

Security Best Practices for Deployments

  • Never commit .env files or API keys to version control
  • Use SCSAI_RELEASE_USER credentials only on trusted networks
  • Enable BOSS_SCHEDULER_CRON=off in production unless you need scheduled tasks
  • Set BOSS_HEAVY_BG=off to prevent resource-intensive background operations
  • Keep LLM API keys rotated and use environment variables, not hardcoded values
← 返回案例列表
分享:
🤖 Try Now →
🤖
🎁