JALK is based on the Linux kernel and inherits all upstream security processes. If you discover a security vulnerability:
- Do NOT file a public GitHub issue
- Email the Linux kernel security team: security@kernel.org
- CC: JALK maintainers at the contact below
For JALK-specific issues (non-upstream code):
- Upstream kernel CVEs: Patched per upstream schedule
- JALK-specific issues: 7-day initial response target
The following are in scope:
- JALK kernel source code (this repository)
- JALK-specific patches in
patches/
The following are out of scope:
- Upstream Linux kernel vulnerabilities (report to security@kernel.org)
- User applications running on JALK
Fingerprint: 2DD9 6596 310B 520B B945 8357 97A3 9EB4 7A2F C589