Security policy¶
Supported versions¶
artifactr is in alpha (0.x). Security fixes are made on main and released in the next version. Once 1.0 ships, the latest minor release receives fixes.
Reporting a vulnerability¶
Please do not open a public issue. Report vulnerabilities privately through GitHub's private vulnerability reporting.
Include what you can of:
- the affected package (
core,workspace,agent,sql,fastapi,mcp) and version or commit - a description of the issue and its impact
- steps to reproduce, or a proof of concept
You can expect an acknowledgement within a week. Once a fix is available, we will publish an advisory crediting you, unless you prefer otherwise.
Scope notes¶
artifactr enforces tenant isolation through scoped workspace handles (ADR-0011). Any way to read or write another tenant's data through the public API is a vulnerability. Authentication itself is the host application's responsibility, through the resolve_actor hook.