Skip to content

Security: zm666999/codex-user-notifier

SECURITY.md

Security Policy

Supported versions

Security fixes are applied to the latest released minor version.

Reporting a vulnerability

Use GitHub private vulnerability reporting for this repository. If private reporting is not enabled yet, open a public issue containing only a request for a private contact channel and no technical details.

Never place credentials, notification tokens, SMTP authorization codes, private Webhook URLs, queue payloads, logs, or exploit details in a public issue or pull request.

Security model

  • A notification is never authorization.
  • The enqueue command must remain a local file write and must not receive channel secrets.
  • Workers read secrets from environment variables or a user-owned env file.
  • The env file and configuration should remain under the current user's Windows profile and must not be committed.
  • Notification messages must not contain passwords, API keys, tokens, cookies, private file contents, or unredacted command output.
  • When monitor_codex_errors is enabled, terminal Codex error fields are forwarded as requested by the user. Those fields can contain local paths, request identifiers, or other diagnostic data; disable the monitor if that disclosure is not acceptable.
  • Webhook endpoints should use HTTPS and scoped credentials.
  • SMTP accounts should use provider-specific application passwords rather than login passwords.
  • The managed AGENTS.md block is advisory behavior for Codex, not a security boundary or guaranteed native lifecycle hook.

There aren't any published security advisories