ClawForge is currently in active development. Security fixes are applied to the
latest main branch and included in the next release.
Please do not report security vulnerabilities in public GitHub issues.
Use one of these private channels instead:
- GitHub Private Vulnerability Reporting (preferred): open a report from the repository's Security tab.
- If private reporting is unavailable, contact maintainers privately through repository ownership contacts and include "Security Vulnerability" in the subject.
Please include as much of the following as possible:
- A clear description of the issue and impacted components.
- Reproduction steps or a proof of concept.
- Potential impact and attack scenario.
- Suggested mitigation, if known.
When a valid report is received, maintainers will:
- Acknowledge receipt within 3 business days.
- Triage severity and affected versions.
- Work on a fix and coordinate a release.
- Credit the reporter (if desired) after the fix is published.
We ask reporters to avoid public disclosure until a fix is available and users have had reasonable time to update.