cep-framework

🔐 Security Policy for the Concept Exchange Protocol (CEP)

Last Updated: 2025-04-28
Applies To: Specification, Reference Agent, Test Suite


🚨 Reporting a Vulnerability

If you discover a security issue related to CEP:

We aim to respond within 72 hours and provide a fix or mitigation plan within 14 days for verified issues.


🧰 Supported Versions

Version Security Fixes Status
v1.0.x ✅ Yes Active
pre-v1 ❌ No Legacy

📜 Scope of Responsibility

We track vulnerabilities related to:


🔏 Non-Security Bugs

For general bugs, please open an issue in the GitHub Issues section with a reproducible example.


🔐 Disclosure Process

  1. You report the issue to [email protected]
  2. We confirm receipt and triage the report
  3. Fixes are developed and tested privately
  4. A GitHub Security Advisory and optional CVE are published
  5. You may be credited unless anonymity is requested

🙏 Thank You

We greatly appreciate responsible disclosures that help us keep CEP secure, trustworthy, and machine-verifiable.