This is a multi-module monorepo. Security fixes usually land in the affected subtree (byclaw-fe, byclaw-be, etc.). Treat main and tagged releases according to your downstream release process.
| Scope | Notes |
|---|---|
Latest main |
Primary line for security assessment |
| Tagged releases | Maintain per your release policy |
(Extend this table with concrete version numbers when you publish releases.)
Do not open a public issue for unfixed security bugs.
Please report privately (use “security” in the subject):
- Email: replace with your security contact
security@example.com - Or GitHub: Security → Report a vulnerability (if enabled)
Include where possible:
- Type of issue and blast radius
- Steps to reproduce or a minimal PoC
- Affected branches, tags, or releases
We will acknowledge receipt and coordinate fix and disclosure timelines. Thank you for responsible disclosure.