Skip to content

Security: BoringInfraCo/Campfire

SECURITY.md

Security policy

Supported versions

Security fixes target the latest published Campfire release. Older snapshots may not receive patches.

Reporting a vulnerability

Please use GitHub's private vulnerability reporting for this repository. Do not include credentials, bearer tokens, private transcripts, customer data, or production workspace contents in a public Issue or Discussion.

Include the affected version, impact, reproduction steps, and any suggested mitigation that can be shared safely. We will acknowledge the report, assess severity, and coordinate disclosure and remediation through the private advisory.

Campfire's security boundaries include workspace authorization before retrieval, distinct human and agent identities, provenance, token secrecy, and transcript isolation. Reports that show one of those boundaries can be bypassed are especially important.

There aren't any published security advisories