Skip to content

Security: iamseth/qi

Security

SECURITY.md

Security policy

qi is experimental, pre-1.0 software. It does not yet have long-term support releases or a guaranteed security-fix or backport window. Security fixes will target the current code and the latest released v0.x line when practical; users should expect to upgrade to receive fixes.

qi's demo CLI does not provide application authorization, peer discovery, or membership policy. A configured replica label is not an authentication credential. Embedding applications are responsible for deciding which authenticated libp2p peers may access each document. See the operational limits, the identity model, and the p2p.SourceResolver package API for the synchronization trust boundaries.

Reporting a vulnerability

Do not disclose suspected vulnerabilities in a public issue, discussion, or pull request. Use GitHub Private Vulnerability Reporting through the repository's Report a vulnerability form instead. Include affected versions, impact, reproduction details, and any suggested mitigation when available.

Maintainers will acknowledge the report, investigate it, and coordinate disclosure and a fix as circumstances permit. Because the project is experimental and maintained on a best-effort basis, no response or remediation deadline is guaranteed.

There aren't any published security advisories