Skip to content

Security: vercel-labs/knowledge-agent-template

Security

SECURITY.md

Security Policy

If you believe you have found a security vulnerability in this repository, please report it privately. Do not open a public GitHub issue, discussion, or pull request.

Reporting a Vulnerability

Use GitHub's private vulnerability reporting on this repository.

Please include as much of the following as you can:

  • A description of the vulnerability and its potential impact
  • The affected component, file paths, or URLs
  • Step-by-step reproduction instructions
  • A proof of concept, if you have one
  • The version, commit, or deployment where you observed the issue

We will investigate all legitimate reports and work to fix confirmed issues as quickly as possible.

Disclosure Policy

We follow coordinated vulnerability disclosure:

  1. We acknowledge receipt of your report.
  2. We assess the report, confirm the issue when valid, and identify affected versions.
  3. We develop and release a fix.
  4. We disclose the issue publicly after a fix is available, and credit you if you want to be credited.

Please keep the report private until we have released a fix and agreed on a disclosure date.

Supported Versions

Only the latest commit on the default branch is supported with security updates.

There aren't any published security advisories