Skip to content

Security: tverney/create-strands-agent

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.1.x

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

Instead, please email the maintainer or use GitHub's private vulnerability reporting.

What to include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response timeline

  • Acknowledgment — within 48 hours
  • Initial assessment — within 1 week
  • Fix or mitigation — depends on severity, but we aim for prompt resolution

Scope

This policy covers the create-strands-agent CLI tool and the project files it generates. It does not cover third-party dependencies — please report those to their respective maintainers.

There aren't any published security advisories