kitsunping

Security Policy

This document explains how to report security issues responsibly and how security-sensitive contributions are handled in this repository.

Reporting a Vulnerability

If you discover a security vulnerability, do not open a public issue.

We will acknowledge receipt as soon as practical and follow up privately.

Disclosure Process

Please avoid public disclosure before maintainers have time to patch.

Scope

Security reports are especially relevant for:

Policy for Binaries (Important)

To reduce supply-chain risk, contributions should avoid adding or modifying prebuilt binaries unless strictly necessary.

If a PR adds or updates binaries (for example under addon/), the PR must include all of the following:

Maintainers may reject binary updates that do not provide sufficient provenance or justification.

Hardening Recommendations for Contributors

Supported Versions

Security fixes are typically applied to the latest maintained branch/version. Older versions may receive fixes at maintainer discretion.