Skip to content

Security: kaspanet/silverscript

SECURITY.md

Security Policy

Supported Versions

Silverscript is experimental and has not reached its first stable release. Security fixes are provided for the latest revision of the master branch only. Older revisions and generated artifacts may not receive security updates.

Reporting a Vulnerability

Please report suspected security vulnerabilities privately through GitHub:

  1. Open the repository's Security advisories page.
  2. Click Report a vulnerability.
  3. Complete and submit the private vulnerability report.

Do not disclose or discuss a suspected vulnerability in public channels (including GitHub issues, discussions, pull requests, X, or Discord) before it has been investigated and a fix has been coordinated.

Please include as much of the following information as possible:

  • A description of the vulnerability and its potential impact.
  • The affected revision, component, and configuration.
  • Steps or a minimal example that reproduces the issue.
  • Any suggested mitigation or fix.
  • Whether the vulnerability has been disclosed elsewhere.

The maintainers will acknowledge the report as soon as practical, investigate it, and coordinate remediation and disclosure with the reporter. Please keep the report and related details private until the maintainers confirm that disclosure is safe.

For ordinary bugs, feature requests, and usage questions that do not have security implications, use the repository's public issue tracker instead.

There aren't any published security advisories