Security fixes are applied to the latest tagged release.
Use a private GitHub security advisory:
https://github.com/satyaborg/revloop/security/advisories/new
Do not open a public issue for a vulnerability. Do not include credentials, proprietary source code, or private reviewer output in a public GitHub artifact.
Include:
- The affected version or commit.
- The triggering workflow and required preconditions.
- The concrete impact.
- A minimal reproduction using synthetic data when possible.
- The smallest mitigation you have verified, if known.
Security reports may cover unsafe Git operations, unintended publication, reviewer sandbox escape, prompt or source disclosure, credential handling, temporary-file retention, and permission-boundary failures.
Provider-side model behavior, service availability, and data retention policies should be reported to the relevant provider unless Revloop bypasses or misrepresents the configured boundary.