If you discover a security vulnerability in Agent Commander:
- Do not open a public GitHub issue.
- Use GitHub's private vulnerability reporting feature or email security@agentcommander.example.
- Include details:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if known)
- We aim to acknowledge reports within 48 hours
- Initial assessment within 7 days
- Remediation timeline shared after triage
- Always set strong
JWT_SECRETandNEXTAUTH_SECRETvalues - Use HTTPS in production
- Restrict dashboard access to trusted networks when possible
- Store secrets in environment variables or a secret manager
- Rotate credentials if exposure is suspected
| Version | Supported |
|---|---|
| Latest | ✅ |