# Security Policy ## Reporting a vulnerability If you discover a security vulnerability in Cave, please report it responsibly. **Do not open a public issue.** Instead, email green@moxielogic.com with: - A description of the vulnerability - Steps to reproduce - The potential impact You should receive a response within 48 hours. We will work with you to understand and address the issue before any public disclosure. ## Scope This policy covers the Cave server, CLI, and runner agent. It does not cover third-party dependencies (Keycloak, PostgreSQL, Podman), though we appreciate reports about how Cave's use of those dependencies may introduce vulnerabilities. ## Supported versions Security fixes are applied to the latest release on the main branch. There are no long-term support branches at this time.