Test / test (push) Successful in 2m4s
Release / gates (push) Successful in 2m5s
Release / build (amd64, freebsd) (push) Successful in 1m27s
Release / build (amd64, linux) (push) Successful in 1m22s
Release / build (amd64, netbsd) (push) Successful in 1m19s
Release / build (amd64, openbsd) (push) Successful in 1m20s
Release / build (arm64, darwin) (push) Successful in 1m21s
Release / build (arm64, freebsd) (push) Successful in 1m26s
Release / build (arm64, linux) (push) Successful in 1m25s
Release / build (arm64, netbsd) (push) Successful in 1m31s
Release / build (arm64, openbsd) (push) Successful in 1m27s
Release / build (loong64, linux) (push) Successful in 1m37s
Release / build (riscv64, linux) (push) Successful in 1m21s
Release / release (push) Successful in 40s
Assisted-by: GLM 5.3 Flash
34 lines
1.1 KiB
Markdown
34 lines
1.1 KiB
Markdown
# Security policy
|
|
|
|
## Supported versions
|
|
|
|
Security fixes go to the newest release and to the `development` branch. Older
|
|
releases do not receive them.
|
|
|
|
## Reporting a vulnerability
|
|
|
|
**Do not open a public issue for a security problem.** A public report tells everyone
|
|
about the flaw before there is a fix. Report it privately to
|
|
**opensource@petrbalvin.org**.
|
|
|
|
Include:
|
|
|
|
- the version or commit you tested, and the platform
|
|
- what the problem is, and what an attacker gains from it
|
|
- the smallest reproducer you have, ideally a test or a single command
|
|
- a suggested fix, if you have one
|
|
|
|
## What to expect
|
|
|
|
- A human reads the report, and you get an acknowledgement.
|
|
- You are kept informed while the fix is being made, and told when it ships.
|
|
- The fix is released before the details are published, and the timing is agreed with
|
|
you.
|
|
- The reporter is credited in the release notes, unless anonymity is requested.
|
|
|
|
## Out of scope
|
|
|
|
- Findings that require the attacker to already run code on the server host, or to
|
|
hold local access to it.
|
|
- Missing hardening with no demonstrated impact.
|