Skip to content

Security: reasonkit/ReasonKit-think

Security

SECURITY.md

Security Policy

Supported versions

Security fixes target the default branch and, when practical, the latest published release. The 0.2.0 release candidate is not yet published; older releases receive fixes on a best-effort basis.

Report a vulnerability

Please report vulnerabilities privately through GitHub's private vulnerability form. If that form is unavailable, email Lenvanderhof@ReasonKit.sh with the subject ReasonKit Think security report.

Include the affected version or commit, impact, reproduction steps, and a minimal proof of concept. Redact credentials, personal data, and unrelated machine details. Do not disclose the report in a GitHub issue or discussion before a fix is coordinated.

The maintainers will acknowledge the report, attempt to reproduce it, assess affected versions, and coordinate remediation and disclosure. Response times depend on severity and maintainer availability; no fixed SLA is promised.

Relevant reports include MCP framing or schema bypasses, fail-open governance, unsafe local-state handling, command execution, credential exposure, and dependency vulnerabilities. Ordinary disagreement with a heuristic score is a quality issue unless it also crosses a documented security or policy boundary.

There aren't any published security advisories