If you discover a security vulnerability in Honzo, please report it privately by opening a security advisory on GitHub or emailing the maintainers.
Please do not report security vulnerabilities through public GitHub issues.
Security issues include:
- Buffer overflows or memory unsafety in the core parser
- Cryptographic weaknesses in the DRM envelope
- Malicious .hzo files that cause denial of service
- Unsafe code in the C FFI boundary
Only the latest release receives security patches.