Skip to content

Security: forjd/agentprov

Security

SECURITY.md

Security Policy

AgentProv is security-adjacent software, but this repository is currently an MVP.

Supported versions

Only the latest main branch is currently supported.

Reporting a vulnerability

Please report security issues privately to the repository owner rather than opening a public issue.

If this project moves to a dedicated organisation, this file should be updated with a dedicated security contact.

Current limitations

  • The local key format is for development and demos only.
  • It is not a replacement for KMS, HSMs, workload identity, or production secret management.
  • Tamper-evident event chains do not protect against a fully compromised host.

There aren't any published security advisories