Skip to content

Security: ermitr/ersec

Security

SECURITY.md

Security Policy

Supported releases

The latest published ERSEC release is the primary supported version.

Reporting a vulnerability in ERSEC

Please do not open a public issue for an undisclosed vulnerability. Use the repository's private GitHub security reporting mechanism when available, or contact the project maintainer through the private channel documented by the repository owner.

Scope

Security reports may include vulnerabilities in:

  • scanner scope enforcement;
  • request transport and evidence handling;
  • Shield enforcement and policy compilation;
  • credential redaction;
  • generated contracts or release workflows;
  • dependency/build/release integrity.

Do not include real secrets, production credentials, or private customer data in a report.

There aren't any published security advisories