Skip to content

Security: avihut/daft

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in daft, please report it privately by emailing:

security@avihu.dev

Please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes (optional)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 1 week
  • Fix timeline: Depends on severity, typically within 30 days

Scope

This policy covers vulnerabilities in:

  • The daft binary and its commands
  • The hooks system trust model
  • Installation scripts

Out of Scope

  • Vulnerabilities in dependencies (report to upstream maintainers)
  • Social engineering attacks
  • Issues requiring physical access to your machine

Disclosure

We follow coordinated disclosure. Once a fix is released, we'll credit reporters (unless anonymity is preferred) in the release notes.

There aren’t any published security advisories