Skip to content

Security: Vanderhell/Nexum

Security

SECURITY.md

Security policy

Supported versions

Nexum is experimental and has no released stable version. Security fixes are made only on the current main branch unless maintainers explicitly document otherwise. No production-support or response-time commitment is implied.

Reporting a vulnerability

Do not open a public GitHub Issue for an undisclosed vulnerability. Use GitHub Private Vulnerability Reporting from the repository's Security tab after that feature is enabled. If private reporting is not available, contact the repository maintainers privately through a repository-owner-controlled channel before sharing technical details. No public security contact address is currently designated.

Include affected commit/version, impact, prerequisites, reproduction details, and any suggested mitigation. Avoid accessing data that is not yours, degrading services, or publishing exploit details before maintainers have had a reasonable opportunity to investigate and coordinate disclosure.

Receipt may be acknowledged without confirming impact. Maintainers will attempt to validate the report, communicate material findings, prepare tests and a fix where appropriate, and credit reporters who request credit. Experimental status does not mean security reports are unimportant.

For the system's technical boundaries, see docs/SECURITY_MODEL.md.

There aren't any published security advisories