Skip to content

Security: similigh/simili-bot

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.0.x

Reporting a Vulnerability

We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly.

How to Report

  1. Do NOT open a public GitHub issue for security vulnerabilities
  2. Email your findings to security@similigh.com
  3. Include as much detail as possible:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

What to Expect

  • Acknowledgment: We will acknowledge receipt within 48 hours
  • Assessment: We will assess the vulnerability and determine its severity
  • Updates: We will keep you informed of our progress
  • Resolution: We aim to resolve critical issues within 7 days
  • Credit: We will credit you in the release notes (unless you prefer anonymity)

Scope

This security policy applies to:

  • The Simili-bot CLI
  • The Simili-bot GitHub Action
  • Official documentation

Out of Scope

  • Third-party dependencies (report to their maintainers)
  • Self-hosted Qdrant instances
  • User-configured API keys or tokens

Security Best Practices

When using Simili:

  1. Rotate API keys regularly
  2. Use GitHub Secrets for storing credentials
  3. Limit token permissions to the minimum required
  4. Review transfer rules before enabling cross-repo transfers

Thank you for helping keep Simili secure! 🔒

There aren’t any published security advisories