Files
Octop/SECURITY.md
jubaoliang 30b17554e3 Fix CI pipeline and make the test suite pass; rename project to Octop
CI:
- Drop Python 3.11 from the test matrix (package requires >=3.12); the
  3.11 jobs failed at `uv sync`. Linux and Windows now test Python 3.12.
- Rename tests/unit/infra/setup/tls/test_store.py -> test_tls_store.py to
  fix the pytest import collision (duplicate basename) that aborted
  collection on the 3.12 job.

Source bugs uncovered by the suite:
- Move ACTOR_SYSTEM to a runtime import in infra/cron/job.py (was wrongly
  placed under TYPE_CHECKING, causing NameError at runtime).
- Add missing users-table columns (login_failed_count, login_locked_until,
  preferences_json) in infra/db/migrate.py for legacy schema repair.
- Make auth.update_me honor explicit nulls via model_dump(exclude_unset=True).
- Relax skills hub endpoints to existence/ownership checks (require_agent_row)
  instead of requiring the agent to be running.
- Marshal WebSocket frames onto the owning event loop in chat/ws.py so the
  starlette TestClient portal does not deadlock.
- Include error details in the browser session 503 response.

Tests:
- Update tests to match current source APIs (harness async create/remove/
  rebuild, FakeHarnessAgent skill methods, workspace nested layout, JWT
  middleware, CLI surface, proactive config defaults, general-assistant
  template manifest).
- Migrate WebSocket tests to starlette TestClient(...).websocket_connect
  (httpx 0.28 removed AsyncClient.websocket_connect).
- Skip memory API tests when the optional harness_memory dependency is absent
  via pytest.importorskip.
- Remove the invalid diagnostic test tests/integration/test_diag_e2e.py
  (no assertions; inspected private internals only).

Also includes the pre-existing uncommitted orca -> Octop rename across docs,
README, LICENSE, Dockerfile and docker assets, as requested.
2026-07-10 00:40:24 +00:00

935 B

Security Policy

Supported versions

Version Supported
latest release on main ✅
older releases best effort

Reporting a vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

We aim to acknowledge reports within 3 business days and provide a fix timeline within 7 business days for confirmed issues.

Scope

Octop is a self-hosted control plane. Operators are responsible for:

  • Securing the host and network exposure of octop run
  • Rotating JWT secrets and admin credentials
  • Reviewing tool guard rules under ~/.octop/security/tool_guard/
  • Protecting LLM API keys and IM channel credentials

See docs/configuration.md for deployment hardening guidance.