Skip to content

Latest commit

 

History

History
18 lines (11 loc) · 604 Bytes

File metadata and controls

18 lines (11 loc) · 604 Bytes

Security Policy

Reporting a vulnerability

Do not open public issue for suspected vulnerability containing sensitive details.

Email repository owner through address listed in Git commit metadata with:

  • Affected version
  • Reproduction steps
  • Impact assessment
  • Suggested mitigation, if known

You should receive acknowledgement within seven days. Public disclosure should wait until fix or coordinated disclosure date is available.

Release signing

Current automated releases are unsigned. Verify release SHA-256 file before installation. Signed and notarized artifacts may be added later.