From f21b127c7830db565012159dcc67d1db3c802349 Mon Sep 17 00:00:00 2001 From: Vantio Date: Tue, 29 Sep 2026 03:25:05 -0400 Subject: [PATCH] remedi(ghx): add SECURITY pointer and drop stale package pins Point vulnerability reports at security@vantio.ai or a private advisory. Refresh CONTRIBUTING so CLI and SDK installs follow current npm and PyPI releases instead of the 0.3.2 and 3.0.2 pins. --- CONTRIBUTING.md | 9 ++++----- SECURITY.md | 14 ++++++++++++++ 2 files changed, 18 insertions(+), 5 deletions(-) create mode 100644 SECURITY.md diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 73fcff00..f235559a 100755 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -4,13 +4,12 @@ Open-core packages (this repo is **Vantio Optics**): -- `packages/vantio-cli` — CLI runner (`@vantio/cli`, currently **0.3.2**) — `npm install -g @vantio/cli` -- `packages/vantio-agent-sdk-py` — Python agent SDK (`vantio-agent-sdk`, currently **3.0.2**) -- `packages/vantio-agent-sdk` — Node.js agent SDK (`@vantio/agent-sdk`) +- `packages/vantio-cli` — CLI runner (`@vantio/cli`). Install the current release from npm: `npm install -g @vantio/cli` +- `packages/vantio-agent-sdk-py` — Python agent SDK (`vantio-agent-sdk`). Install the current release from PyPI: `pip install vantio-agent-sdk` +- `packages/vantio-agent-sdk` — Node.js agent SDK (`@vantio/agent-sdk`). Install the current release from npm. - `packages/vantio-optics-mcp` — Optics MCP (`@vantio/optics-mcp`) — observe only -- `packages/vantio-gate-mcp` — Gate MCP (`@vantio/gate-mcp`) — dry-run evaluate only (legacy/compat; Gate is the internal Enforce function inside Phantom Engine, not a standalone SKU) -Phantom Engine (Linux host protection) lives in a separate repository. Do not add it here. +Phantom Engine (Linux host protection) lives outside this repository. Do not add it here. The product page is https://vantio.ai/phantom. ## Development diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 00000000..2ace1513 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,14 @@ +# Security Policy + +This repository follows the Vantio organization security policy for public Optics surfaces. + +Report a suspected vulnerability here: + +- Email **security@vantio.ai** (preferred) +- Or open a **private** GitHub Security Advisory on this repository, if that is enabled + +Do not open a public issue for an unfixed vulnerability. Do not attach secrets, customer data, or prompts and completions. + +We acknowledge reports when we can. We do not promise a response time. + +Phantom Engine source is private. Do not use this repository to disclose or contribute host-control issues. The product page is [vantio.ai/phantom](https://vantio.ai/phantom).