Vulnerability reporting policy for the C-axis trust program: private disclosure address, response process, and an honest pre-1.0 supported- versions statement (no fabricated version table, no SBOM claim).
1.1 KiB
Security policy
Reporting a vulnerability
Report privately to security@fromaitochitta.com - do not open a public issue. Canonical repository: https://git.fromaitochitta.com/open/repo-mailbox
Please include the affected version or commit, a minimal reproduction, and the impact you see. We acknowledge every report within 5 working days, agree a fix and disclosure timeline with the reporter, and aim to disclose within 90 days of the initial report.
Response process
- Acknowledge within 5 working days.
- Triage and confirm severity within 10 working days.
- Develop and test a fix.
- Publish an advisory and credit the reporter unless they prefer to remain anonymous.
Supported versions
This project is pre-1.0 (a single continuous 0.x line, currently in the 0.25 series) and carries no parallel maintenance branches. Only the latest tagged release receives security fixes; please upgrade to the latest release before reporting.
Advisories
Security-relevant fixes are recorded in CHANGELOG.md. Given the project's current scale, we do not yet publish separate signed advisories.