Skip to content

Security: Scarabaeus1031/NEXAHEDRON

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Do not open a public issue for a suspected vulnerability or include private Human material in a report.

Email contact@nexah.de with the subject [SECURITY] NEXAHEDRON. Include:

  • the affected version, revision or public URL;
  • a minimal reproduction;
  • the expected and observed behavior;
  • the likely impact;
  • whether Human material, credentials or provenance may have been exposed.

Never send real secrets, access tokens or third-party personal material. Use redacted or synthetic examples.

Receipt should be acknowledged within seven calendar days. Acknowledgement is not confirmation of a vulnerability or a promise of a remediation date.

Supported versions

Only the latest explicitly published NEXAHEDRON release is eligible for security fixes. Working-tree snapshots, historical Alpha records and forks are not supported releases. Until a first release is published, no version is represented as production-supported.

Scope

Reports may cover the NEXAHEDRON application, its same-origin transport route, deployment configuration and accidental disclosure of Human material. Vulnerabilities in NEXAH, ORION, hosting providers or external sources should also be reported to their respective owners. NEXAHEDRON will not silently assume another subsystem's authority.

There aren't any published security advisories