Security: Donkey-Development-Kit/donkey-development-kit
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Blocked PII echoed in PIIDetected messages and doctor output; secrets in DonkeyConfig repr; end-user id sent as an unused headerGHSA-38r7-5g44-q43f published
Oct 2, 2026 by tbolis-at-mulesoftModerate -
Working-directory .donkey-kit.toml can redirect environment-held credentials to an arbitrary host, including over plain HTTPGHSA-852f-22j5-pcm9 published
Oct 2, 2026 by tbolis-at-mulesoftModerate -
Control-plane OAuth token is attached to data-plane (LLM proxy) requests, and framework clients forward LLM-proxy credentials across redirectsGHSA-v7vr-6p6h-78jf published
Oct 2, 2026 by tbolis-at-mulesoftHigh
Learn more about advisories related to Donkey-Development-Kit/donkey-development-kit in the GitHub Advisory Database