| Version / branch | Supported |
|---|---|
Latest main and release tags |
Yes |
| Older tags | Best-effort |
Security fixes land on main first; maintainers may backport critical fixes to recent tags on a case-by-case basis.
Please do not open public GitHub issues for exploitable security bugs.
Report privately by one of:
- GitHub Security Advisories — Open a private advisory on this repository (preferred once the repo is public).
- Email —
info@rileybetts.ai(Riley Betts Ltd)
Include:
- Description and impact
- Steps to reproduce
- Affected commit, tag, or release if known
- Proof-of-concept if available
We aim to acknowledge reports within 5 business days and will coordinate disclosure timing with you.
In scope:
- Receipt forgery, accept/reject bypass, or cross-suite confusion in
LeanTee.TeeReceipt/lean_tee_receipt - gRPC
Execute/AcceptReceipt/Provehandling inteeServerandprove_server - ACL, API key, or tenant isolation bugs in the control plane
- Secret leakage when
LEAN_TEE_CONFIDENTIALITY=localis enabled
Out of scope (by design — see docs/VS_NITRO.md):
- Host OS root reading guest memory
- SP1 proving machine seeing public inputs/outputs
- Mock prove (
lean-tee-v1) used as production attestation
Upstream SP1 / Succinct prover issues should be reported to succinctlabs/sp1 unless lean-tee glue code is clearly at fault.
We appreciate responsible disclosure and will not pursue legal action against researchers who follow this policy in good faith.