Skip to content

Security: iam-brain/opencode-codex-auth

Security

SECURITY.md

Security Policy

Supported versions

Security fixes are prioritized for the latest released version of @iam-brain/opencode-codex-auth.

Reporting a vulnerability

Please do not open public issues for security reports.

Use GitHub Security Advisories for private disclosure:

  1. Go to the repository Security tab.
  2. Click Report a vulnerability.
  3. Include impact, reproduction steps, and affected version.

If private advisory reporting is unavailable, open a minimal issue without sensitive details and request a private contact path.

What to include

  • Affected version/tag
  • Reproduction steps
  • Expected vs actual behavior
  • Logs or screenshots with secrets redacted

Response expectations

  • Initial triage acknowledgement target: within 5 business days
  • Remediation target: based on severity and exploitability

There aren’t any published security advisories