Security fixes are considered for the current main branch and the latest tagged prerelease. Older prereleases may not receive patches.
As of September 8, 2026, Tarfio is a no-real-funds beta. Test credits have no cash value. Do not use it to hold funds, process deposits, or pay creators.
Do not file a public issue for a suspected vulnerability.
Use GitHub private vulnerability reporting for this repository when available. Otherwise, contact the repository owner through their GitHub profile and request a private channel. Include:
- affected commit or release;
- deployment mode and configuration relevant to the issue;
- reproduction steps or a minimal proof of concept;
- expected and observed impact;
- whether secrets or personal data may have been exposed.
Do not include live credentials, private keys, access tokens, database dumps, or personal data. Use test accounts and test credits only.
Maintainers will acknowledge a complete report when it is read, investigate it, and coordinate disclosure when practical. No response-time or remediation-time SLA is offered for the beta.
Good-faith testing should stay within systems and accounts you own or have permission to test. Do not access other users' data, degrade shared services, send traffic to third-party MCP servers without permission, or attempt real financial transactions.
Operators are responsible for TLS, network isolation, secret storage, database encryption and backups, log access, dependency patching, key rotation, monitoring, and incident response. Review Known Limitations and the Threat Model before deployment.
Spend-token deployments must configure an explicit active signing kid and a
public verification keyring. Retain previous public keys only for the bounded
token-lifetime overlap, and treat unexpected missing or unknown kid failures
as configuration or tampering signals rather than enabling fallback behavior.