Skip to content

Security: CarlosDlw/hydralock

Security

SECURITY.md

Security Policy

Supported Versions

This project currently supports the master branch only.

Reporting a Vulnerability

Please do not disclose vulnerabilities publicly before a fix is available.

Report privately using GitHub Security Advisories (preferred), or by contacting the maintainers directly.

Include:

  1. affected component/file;
  2. impact summary;
  3. proof of concept or reproduction steps;
  4. suggested mitigation (if available).

Response Targets

  • Initial triage: within 72 hours
  • Status update: within 7 days
  • Fix timeline: depends on severity and complexity

Scope Notes

HydraLock is a cryptographic container format implementation. Issues involving confidentiality, integrity, key handling, wrapper validation, parser fail-open behavior, and downgrade/rewrap bypasses are considered high priority.

There aren't any published security advisories