Skip to content

Security: specdog/dotdog

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in dotdog, please report it privately. Do not open a public issue.

Email: security@specdog.dev (or open a private security advisory on GitHub)

We will respond within 48 hours and work on a fix.

Supported Versions

Version Supported
0.4.x Yes
< 0.4.0 No

Scope

  • MCP server input validation
  • Path traversal in file operations
  • YAML injection in .dog files
  • Token savings calculation integrity

There aren't any published security advisories