Please do not open a public issue for a security problem.
Report it privately by either:
- using GitHub's "Report a vulnerability" button on the affected repository (private vulnerability reporting), if it is enabled; or
- emailing Timothy.Gregg@complete.tech with the repository, a description of the issue, steps to reproduce, and any suggested fix.
Please do not include real credentials or personal data in your report.
This is a small team and most projects are early-stage, so we cannot promise fixed response times. We will make a good-faith effort to acknowledge reports, investigate, and credit reporters who want credit.
This policy covers public repositories in the CompleteTech-LLC organization. Forked projects (for example openclaw, unstract, herdr) should also be reported upstream where the issue is in upstream code.