Do not open a public GitHub issue for security vulnerabilities.
Report vulnerabilities privately via GitHub Security Advisories. You will receive a confirmation within 2 business days and a triage decision within 5 business days.
| Severity | Definition | Fix Target |
|---|---|---|
| Critical | Remote code execution, attestation bypass, signing key extraction, audit chain forgery | 30 days from confirmed report |
| High / Medium / Low | All other confirmed vulnerabilities | 90 days from confirmed report |
Timeline starts when the issue is confirmed as a valid vulnerability, not on initial receipt. We will communicate progress at least every 14 days during active remediation.
The following components are in scope:
policy_bundle_hash, audit_chain_root, tee_public_key); any path by which a valid audit entry could be forged or suppressedThe following are not eligible for a coordinated disclosure:
If you are unsure whether an issue is in scope, report it anyway and we will triage.
Reporters of confirmed, in-scope vulnerabilities will be acknowledged by name (or handle, if preferred) in the release notes of the fix. We will not publish details of the report without your consent. If you prefer to remain anonymous, say so in your advisory submission and we will honor that.