Back to home

Security Policy

Reporting a vulnerability

Please report security issues privately. Do not open a public issue for vulnerabilities.

Include steps to reproduce and the affected component (worker, extension, web, or shared). We aim to acknowledge within a few days.

Scope and design notes

Hopgo is built so that a compromise has a small blast radius:

Supported versions

This project is pre-1.0. Only the latest release receives security fixes.