Skip to content

Security: ComfyAssets/ComfyUI_PromptManager

SECURITY.md

🔐 Security Policy

Supported Versions

Security updates are provided for the actively maintained versions of ComfyUI_PromptManager.

Version Supported
main / latest
Older releases

Users are encouraged to stay up to date with the latest version.


Reporting a Vulnerability

For most security-related issues, please open a GitHub issue in this repository.

When opening an issue:

  • Clearly describe the problem
  • Include steps to reproduce
  • Mention the affected version or commit
  • Avoid posting secrets, tokens, or private data

Sensitive Issues

If you believe the issue:

  • Could enable remote code execution
  • Exposes credentials or private data
  • Is actively exploitable in the wild

Please use GitHub Security Advisories instead:

  • Go to the Security tab
  • Click Report a vulnerability

Response Expectations

  • Issues are typically reviewed within a few days
  • Valid issues will be labeled and tracked publicly
  • Fixes may be discussed openly and merged transparently

Scope

This policy applies to:

  • Code contained in this repository
  • Default configurations and documented usage

It does not cover:

  • Third-party nodes, models, or extensions
  • User workflows, prompts, or local environment issues

Thank You

Community reports and transparency help keep the project healthy. Thanks for contributing responsibly.

There aren’t any published security advisories