Skip to content

Security: relayforge-ai/carapace-protocol

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Carapace Protocol, please report it responsibly:

  1. GitHub Security Advisory — Open a security advisory on this repository (preferred).
  2. Email — Send details to security@relayforge.tools.

Please do not open a public issue for security vulnerabilities.

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgement — within 48 hours
  • Initial assessment — within 5 business days
  • Fix or mitigation — as soon as reasonably possible, coordinated with the reporter

Scope

This policy covers:

  • The Carapace Protocol specification
  • The carapace-sdk Python and TypeScript packages
  • The ARIA registry API

Supported Versions

Version Supported
Latest Yes

There aren't any published security advisories