Supported versions
Historical 3.x artifacts are retained for traceability, but they are not an active compatibility or security-support surface.
Report a vulnerability
Use GitHub private vulnerability reporting. Do not open a public issue for a suspected vulnerability.
Include the affected plugin and version, Codex, Python, and operating system versions, impact, reproduction steps, and a minimal proof of concept. Remove API keys, tokens, private prompts, personal paths, and customer data.
Gloamere will acknowledge the report through GitHub and coordinate disclosure after a fix is available. The beta does not promise a fixed response-time SLA.
Security boundary
- The prepared plugins contain no Gloamere backend, telemetry, hooks, MCP servers, or background services.
- Plugins still operate within the permissions and tools granted to Codex; users should review requested actions and protect local inputs.
- Install immutable tagged releases and compare archives against their published SHA-256 sidecars.
- Missing, malformed, truncated, or unknown Eval evidence is non-verified. A model statement is not proof that a Skill was loaded.