Skip to content

Security: Delego-Dev/sample-app

Security

SECURITY.md

Security Policy

This is a reference sample app — a ~150-line FastAPI service that demonstrates how to build on delego. It is meant to be read and adapted, not deployed as-is in production.

Reporting a vulnerability

Please do not open a public issue for security vulnerabilities.

Report privately via GitHub's private vulnerability reporting, or email koishore@gmail.com. We aim to acknowledge within 72 hours.

Scope

  • In scope: a flaw in how this sample uses delego that teaches an unsafe pattern — e.g. the example BrokerAdapter executing an action other than the one that was authorized, or the API releasing an approval that doesn't match the proposed action.
  • Out of scope: the demo's lack of production hardening (no auth on the endpoints, single-worker file-backed state) — these are documented simplifications, not bugs. A real deployment must add its own authentication, transport security, and a credentialed broker.
  • delego itself: report against delego, not here.

Supported versions

Only the latest commit on main is maintained; the app tracks the newest released delego.

There aren't any published security advisories