nova-tools has a security page
nova-tools has a security page. These binaries run with an adopting line's privileges, and until now the only word on reporting a defect in one was a bullet in CONTRIBUTING.
What ships.
SECURITY.md: how to report, with the route's limits stated rather than implied. Mail is unencrypted and unauthenticated, the second mailbox is no more private than the first, nothing about the route is anonymous, and the one anchor a reporter can check without trusting mail is this file's own commit history, with what that anchor does not prove said beside it.- The vulnerability classes as properties, so an attack nobody has named yet still has a class: a check answering clear for a case it did not check; reaching any destination the caller did not name, or overwriting one named only as an input; content changing what a tool does; losing a fuse, or clearing one by a route
SPEC.mddoes not authorize; untrusted content reaching a reader, human, terminal or model, as something the tool said rather than quoted, or carrying more of a protected record than its grammar requires; state left half-written; a check that cannot run or cannot finish; and anything distributing something under these names that was not built from this repository. - The ask that binds whatever a reporter decides: do not publish a working bypass before it is fixed, because these are binaries with an installed base and no update channel.
CONTRIBUTING.mdpoints at the page and no longer restates the route.
Ten revisions, each read cold on both models; every block after the first fell inside the previous revision's repair, and what converged was deletion.