Skip to content

Security: simonmak-ascent/opencode-workbench

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Do not open a public issue for security problems. Report privately, either via GitHub's private vulnerability reporting on this repository (Security → Report a vulnerability), or by emailing simon.pl.mak@gmail.com with SECURITY in the subject.

Include: affected component (mcp-server/, scripts, opencode.json), reproduction steps, and impact. We aim to acknowledge within 3 business days.

Supported versions

The latest commit on main is the only supported version.

Secrets

This repository must never contain secret values. Provider and MCP credentials are referenced only through {env:VAR} placeholders and are supplied at runtime from the operator's environment (~/.env.workbench or the platform's secret store).

The mcp-server/ clone tool writes only an empty template (~/.env.workbench, mode 600) to target machines; it never reads, transmits, or commits secret values.

Automated controls

  • gitleaks runs on every push and pull request (.github/workflows/secret-scan.yml).
  • GitHub secret scanning and push protection are enabled on the repository.

There aren't any published security advisories