Report security vulnerabilities privately to security@agent-assembly.com. Do not open a public issue or discussion for a security report.
| Response stage | Target |
|---|---|
| Acknowledgement | Within 2 business days |
| Initial assessment | Within 5 business days |
Legacy address.
security@agent-assembly.devremains a legacy compatibility alias. During the in-progress migration to the canonicalsecurity@agent-assembly.comidentity, the legacy address continues to receive mail via Cloudflare Email Routing, so a report sent there still reaches us. The canonical mailbox is not yet live-sending.
| Version | Supported |
|---|---|
| 0.0.x | ✅ |
| < 0.0.1 | ❌ |
Once we ship v0.1.0, we'll update this table with the supported window (typically the latest minor + one previous).
- We'll work with you on a fix and coordinated disclosure timeline.
- We'll credit you in the release notes for the fixed version, unless you prefer to remain anonymous.
For non-security bugs, please use the regular issue tracker on the relevant repo.