Skip to content

Security: PLASMA-FR/ccbridge

Security

SECURITY.md

Security Policy

Supported Versions

This project is currently maintained on the latest main branch state only.

Reporting a Vulnerability

Do not open public GitHub issues for security-sensitive problems.

Report vulnerabilities privately to the repository owner with:

  • a concise description of the issue
  • affected files or endpoints
  • reproduction steps
  • impact assessment
  • any suggested mitigation

If the issue involves local auth tokens, Codex account state, or exposed proxy access, rotate the affected credentials before sharing broader details.

Scope Notes

This bridge is intended for local-only use by default. Security-sensitive areas include:

  • Anthropic-compatible proxy authentication
  • Codex OAuth token storage under account-specific CODEX_HOME
  • dashboard actions that apply Claude settings
  • any configuration that changes host binding or enables CORS

There aren't any published security advisories