Security Policy

July 8, 2026 ยท View on GitHub

Supported Versions

The main branch is the supported version of this Codex plugin wrapper.

The Tree Ring Memory framework and CLI are maintained in the canonical repository:

https://github.com/TerminallyLazy/Tree-Ring-Memory

Reporting A Vulnerability

Open a private security advisory on GitHub when available, or open a public issue with sensitive details removed:

https://github.com/TerminallyLazy/tree-ring-memory-codex-plugin/issues

Do not include secrets, tokens, private memory contents, or personal data in a public issue.

Data Handling

This wrapper plugin contains guidance files only. It does not run a background service, include remote MCP servers, collect telemetry, or store credentials.

Tree Ring Memory is designed for explicit agent-mediated memory actions. Store only concise decisions, lessons, warnings, and evidence references that are useful, source-linked, and privacy-safe. Do not store raw transcripts, secrets, private keys, tokens, or raw chain-of-thought.