Skip to content

Security: Th3Mouk/Maestro

SECURITY.md

Security Policy

Reporting

Report vulnerabilities through a private channel before any public disclosure.

Sensitive areas

  • pack hook resolution and execution
  • write and branch policies
  • generated runtime projection
  • GitHub integration and associated permissions
  • manipulation of repositories cloned into repos/

What to include

  • a minimal reproduction scenario
  • the impact on workspaces, packs, or target repositories
  • whether privilege escalation or scope escape is possible

There aren't any published security advisories