| Version | Supported |
|---|---|
| 1.1.x | Yes |
| < 1.1 | No |
Do not open public GitHub issues for security vulnerabilities.
Use GitHub's private vulnerability reporting: https://github.com/Fmarzochi/EGC/security/advisories/new
Alternatively, email fmarzochi@gmail.com.
Include in your report:
- A description of the vulnerability
- Steps to reproduce
- Affected version(s)
- Potential impact
- Acknowledgment: within 72 hours
- Status update: within 14 days
- Resolution or mitigation: within 90 days of confirmed vulnerability
This policy covers the EGC repository, including:
- Core runtime scripts (
scripts/) - MCP server sources (
mcp/servers/) - Installation scripts (
install.sh,install.ps1) - Hook and skill definitions (
hooks/,skills/)
The following are not treated as vulnerabilities under this policy:
- Vulnerabilities in third-party dependencies (report upstream)
- Issues requiring physical access to the host machine
- Denial-of-service against a local-only runtime with no network exposure
- Behaviors that require the reporter to already have write access to the host
Secrets and credentials used by the project are managed as follows:
- Storage: The secrets the workflows need are stored exclusively as GitHub Actions repository secrets. They are never committed to the repository or stored in plain text on disk. The
GITHUB_TOKENis not stored at all: GitHub creates it for each workflow run. npm publishing uses trusted publishing (OIDC), so no npm token is stored either. - Access: Only the project owner has access to configure repository secrets. GitHub Actions workflows access secrets only via the
secrets.*context, scoped to the specific job that needs them. - Rotation: Secrets are rotated immediately upon suspected or confirmed compromise.
- Scope: Secrets are scoped to the minimum necessary permissions. The release job receives a short-lived OIDC token valid for that run only. The
GITHUB_TOKENis granted only the permissions declared in each workflow'spermissions:block. - Audit: Secret usage is visible in the GitHub Actions run logs (values are masked). Any addition of new secrets requires maintainer approval.