Voss
Security disclosure

Report security issues without public details.

Voss is local-first developer tooling, so security reports should protect repos, credentials, and exploit details. Do not paste secrets, token values, or working exploit steps into a public issue.

How to report

Open a minimal GitHub issue that says you have a security report and need a private channel. Include the affected package or surface, impact summary, and safe contact path. Leave exploit details, private repo names, and credentials out of the issue.

Handling expectations

Voss does not currently publish a bug bounty program. Reports are handled as coordinated disclosure: confirm receipt, reproduce impact, ship a fix, and credit the reporter when they want attribution.

In scope

  • Voss CLI and harness behavior
  • .voss workflow-control files and runtime behavior
  • npm, PyPI, and container packaging paths
  • Marketing and documentation site behavior

Out of scope

  • Social engineering
  • Spam or denial-of-service testing
  • Destructive testing against real projects
  • Reports that require leaking secrets into a public issue