Skip to content

Security: adarshkr/cairn

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Do not report security vulnerabilities through public GitHub issues.

Use GitHub's private vulnerability reporting:

  1. Go to the Security tab of this repository
  2. Click Report a vulnerability
  3. Fill out the form

If that's unavailable, email: kr.adarsh002@gmail.com

What to expect

  • Acknowledgment: within 3 business days
  • Initial assessment: within 14 days
  • Disclosure timeline: coordinated, typically 90 days from report

Severity SLAs

Severity Patch SLA
Critical 7 days
High 30 days
Medium 60 days
Low Next minor release

Supported Versions

Cairn is pre-1.0. Only the main branch receives security updates until the first stable release.

Out of Scope

  • Vulnerabilities in vendored dependencies (report upstream)
  • Issues requiring physical access
  • Social engineering

There aren't any published security advisories