Skip to content

Security: warpdotdev/cro-agent-oss

SECURITY.md

Security Policy

Reporting a Vulnerability

To report a security vulnerability in this repository, please email security@warp.dev.

Do not open a public GitHub issue for security vulnerabilities. Responsible disclosure gives us time to fix the issue before it is publicly known.

Please include:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce or a proof-of-concept
  • Any suggested mitigations if known

We will acknowledge receipt within 2 business days and aim to resolve confirmed vulnerabilities within 90 days.

Scope

This is a reference implementation. If you find a vulnerability in the pattern or configuration guidance (e.g. an unsafe shell command, a credential-handling flaw, or an injection risk in the SQL templates), please report it.

Issues with third-party integrations (Notion, BigQuery, Slack, Metabase, Sanity) should be reported directly to those vendors.

There aren't any published security advisories