| Version | Supported |
|---|---|
latest (main) |
✅ |
Please do not open a public issue for security vulnerabilities. Instead, report them privately:
- Email edy.cu@live.com, or
- Use GitHub's private vulnerability reporting (Security → Report a vulnerability).
You'll get an acknowledgment within 48 hours and a resolution timeline after triage. Please give us a reasonable window to patch before public disclosure.
- Reports are ed25519-signed and content-addressed;
armsmith verifyre-checks the chain. If you find a way to makeverifypass on a tampered report, that is a security bug — please report it privately. - Private signing keys live under
~/.armsmith(orARMSMITH_KEY_DIR) and must never be committed;.gitignoreexcludes*.pemand.armsmith/.