Skip to content

Security: duckcode-ai/dbt-spec-kit

Security

SECURITY.md

Security

Supported versions

Security fixes are accepted for the latest released version of dbt-spec-kit. Older versions may be patched when a fix is low-risk and clearly applicable.

Reporting a vulnerability

Do not open a public issue for a suspected security vulnerability.

Email the maintainers at open-source@duckcode.ai with:

  • affected version or commit
  • reproduction steps
  • impact assessment
  • any suggested fix

You should receive an initial response within 5 business days.

Scope

dbt-spec-kit is a local CLI and markdown asset package. The CLI should not collect telemetry, phone home, or require hosted services. Report any behavior that violates that expectation.

There aren't any published security advisories