Skip to content

Security: TerminallyLazy/tree-ring-memory-codex-plugin

Security

SECURITY.md

Security Policy

Supported Versions

The main branch is the supported version of this Codex plugin wrapper.

The Tree Ring Memory framework and CLI are maintained in the canonical repository:

https://github.com/TerminallyLazy/Tree-Ring-Memory

Reporting A Vulnerability

Report vulnerabilities privately through the canonical repository's GitHub security advisory form:

https://github.com/TerminallyLazy/Tree-Ring-Memory/security/advisories/new

Use the canonical issue tracker only for non-sensitive support:

https://github.com/TerminallyLazy/Tree-Ring-Memory/issues

Never include vulnerability details, secrets, tokens, private memory contents, or personal data in a public issue.

Data Handling

This wrapper plugin contains guidance files only. It does not run a background service, include remote MCP servers, collect telemetry, or store credentials.

Tree Ring Memory is designed for explicit agent-mediated memory actions. Store only concise decisions, lessons, warnings, and evidence references that are useful, source-linked, and privacy-safe. Do not store raw transcripts, secrets, private keys, tokens, or raw chain-of-thought.

There aren't any published security advisories