Skip to content

Security: anivar/decern

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.1.x Yes

Only the latest 0.1.x release receives security fixes.

Reporting a Vulnerability

Report vulnerabilities privately using GitHub's private vulnerability reporting: open the repository's Security tab and click Report a vulnerability to open a draft advisory. Please do not open public issues for security reports.

What to Expect

  • Acknowledgement of your report.
  • Coordinated disclosure: we investigate, prepare a fix, and agree on a public disclosure timeline with you before any details are published.

decern's safety invariants are machine-checked over the entire input space, but the project is pre-1.0 — reports of gaps in what the proofs actually cover are especially welcome.

There aren't any published security advisories