Skip to content

Security: jfrog/opencode-jfrog-plugin

Security

SECURITY.md

Security

Reporting a vulnerability

Please report security issues responsibly so we can address them before public disclosure.

Include steps to reproduce, affected versions or commits, and impact if known.

Scope

This repository ships an OpenCode plugin (a thin config hook plus vendored skills, published to npm).

Do not commit secrets, API keys, or credentials. Skill runtime data under **/local-cache/ must not be checked into git.

There aren't any published security advisories