Skip to content

Security: GoldenHCH/inside-the-build

SECURITY.md

Security policy

Supported versions

Only the latest published beta receives security fixes during the 0.x design-partner period. Older prereleases are unsupported.

Version Supported
Latest beta dist-tag Yes
Earlier prereleases No

Report a vulnerability privately

Use GitHub's private vulnerability reporting. Do not open a public issue, post in Discord, or include real candidate or employer data.

Include:

  • the affected version and platform;
  • a synthetic proof of concept;
  • expected and observed impact;
  • suggested mitigations, if known.

The maintainer will acknowledge reports on a best-effort basis, validate impact, coordinate a fix and advisory, and credit reporters who want attribution. No bounty program or response SLA is currently offered.

Security model

Inside the Build is local-first and has no hosted service, but it reads sensitive local session files and passes extracted text to a local coding agent. Important unresolved risks, including prompt injection and lack of built-in redaction, are documented in Known limitations. Those disclosed limitations are not themselves security vulnerabilities unless a report demonstrates impact beyond the documented model.

There aren't any published security advisories