cmcp

Security Policy

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Report vulnerabilities privately via GitHub Security Advisories. You will receive a confirmation within 2 business days and a triage decision within 5 business days.

Response SLAs

Severity Definition Fix Target
Critical Remote code execution, attestation bypass, signing key extraction, audit chain forgery 30 days from confirmed report
High / Medium / Low All other confirmed vulnerabilities 90 days from confirmed report

Timeline starts when the issue is confirmed as a valid vulnerability, not on initial receipt. We will communicate progress at least every 14 days during active remediation.

Scope

The following components are in scope:

Out of Scope

The following are not eligible for a coordinated disclosure:

If you are unsure whether an issue is in scope, report it anyway and we will triage.

Credit

Reporters of confirmed, in-scope vulnerabilities will be acknowledged by name (or handle, if preferred) in the release notes of the fix. We will not publish details of the report without your consent. If you prefer to remain anonymous, say so in your advisory submission and we will honor that.