Skip to content

Security: logser13/opencode-multidevice-sync

Security

SECURITY.md

Security and privacy

This preview has no security warranty. Keep independent backups and one active device.

Report reproducible non-sensitive bugs in GitHub Issues with artificial session IDs and minimal synthetic fixtures. Do not post tokens, private repository URLs, real conversations or database dumps.

For an exploitable vulnerability, use GitHub private vulnerability reporting if available. Otherwise open an issue requesting a private reporting channel without exploit details or personal data. Do not send unsolicited real data.

Synced plugins execute local code. Treat repository write access as access to the agent environment. Keep credentials and browser profiles local; a private repository is not end-to-end encryption.

No postinstall script changes OpenCode configuration. Review the migration guide and install only trusted package artifacts.

There aren't any published security advisories