Skip to content

Security: owainlewis/cortex

SECURITY.md

Security Policy

Supported Versions

Cortex is a small pre-1.0 project. Security fixes target the current main branch and the latest published GitHub Release. Older releases and Nightly artifacts are not supported.

Support means that a fix, when made, is applied to the supported code. It does not promise a response time, remediation deadline, or release schedule.

Reporting a Vulnerability

Do not report suspected vulnerabilities in a public issue or discussion.

Use GitHub's private vulnerability reporting form. Include:

  • a clear description of the vulnerability and its impact;
  • the affected release, commit, or component;
  • reproduction steps or a proof of concept;
  • relevant macOS and terminal details;
  • any known mitigations.

Reports are reviewed as maintainer availability permits. When practical, the maintainer and reporter will coordinate disclosure through the private advisory before details are made public.

If GitHub's private reporting form is unavailable, open a public issue without vulnerability details and ask the maintainer to arrange a private reporting channel.

There aren't any published security advisories