Skip to content

Security: copyleftdev/symgliph

Security

SECURITY.md

Security policy

Supported versions

Until the first stable release, security fixes target the latest main branch. Older draft artifacts may be replaced rather than patched in place unless their identifier has been declared immutable by a release.

Report a vulnerability

Please use Report a vulnerability in the Security tab of copyleftdev/symgliph to open a private GitHub Security Advisory. Do not disclose an unpatched vulnerability in a public issue.

Include the affected revision, threat model, reproduction, impact, and any known workaround. Reports involving path traversal, digest verification, stale-source acceptance, binary-envelope parsing, prompt-boundary confusion, or credential handling are especially useful.

You should receive an acknowledgement within seven days. Resolution timelines depend on severity and whether a protocol revision is required.

Scope

The protocol proves artifact identity under its declared algorithms. It does not assert that indexed source is trustworthy, licensed, safe to execute, or free of prompt injection.

There aren't any published security advisories