Skip to content

Security: guaracloud/positron

Security

SECURITY.md

Security policy

Do not report suspected vulnerabilities, credentials, key material, tenant data, or exploit details in a public issue.

Use the repository's private vulnerability-reporting flow from the GitHub Security tab. If that flow is unavailable, contact the Guara Cloud security owner through a private established channel before sharing sensitive details.

Reports should include the affected revision or artifact digest, impact, reproduction conditions, and any safe minimized reproducer. Use synthetic values only. Positron retains failing security evidence and does not treat a scanner pass as proof that a vulnerability is impossible.

There aren't any published security advisories