| Version | Supported |
|---|---|
| 0.7.x | ✅ |
| < 0.7 | ❌ |
Do not report security vulnerabilities through public GitHub issues.
Instead, please report them privately through GitHub Security Advisories: Report a vulnerability. This opens a private advisory visible only to the maintainers — no email or third-party domain is involved.
You should receive a response within 48 hours. If you do not, please follow up by opening a (non-sensitive) GitHub issue asking a maintainer to check the private advisory queue.
Please include the following information:
- Type of issue (e.g., buffer overflow, SQL injection, cross-site scripting, etc.)
- Full paths of source file(s) related to the manifestation of the issue
- The location of the affected source code (tag/branch/commit or direct URL)
- Any special configuration required to reproduce the issue
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if possible)
- Impact of the issue, including how an attacker might exploit the issue
All commits to protected branches must be signed. This ensures:
- Commit authorship is verified (non-repudiation)
- Supply chain integrity (SLSA Level 2+)
- Defense against commit spoofing attacks
Option 1: GPG Key
# Generate a GPG key
gpg --full-generate-key
# Get your key ID
gpg --list-secret-keys --keyid-format LONG
# Configure git
git config --global user.signingkey YOUR_KEY_ID
git config --global commit.gpgsign true
# Add your public key to GitHub
gpg --armor --export YOUR_KEY_ID
# Paste output at: GitHub → Settings → SSH and GPG keysOption 2: SSH Key (Simpler)
# Configure git to use SSH for signing
git config --global gpg.format ssh
git config --global user.signingkey ~/.ssh/id_ed25519.pub
git config --global commit.gpgsign true
# Add your SSH key to GitHub for signing
# GitHub → Settings → SSH and GPG keys → New SSH key
# Select "Signing Key" as the key type# Verify a commit signature
git verify-commit HEAD
# Show signature in log
git log --show-signature -1We use multiple layers of dependency security:
- cargo-audit: Checks dependencies against RustSec advisory database
- cargo-deny: Enforces license compliance and bans problematic crates
- Dependabot: Automated security updates
- SBOM: Every release includes a Software Bill of Materials
- All dependencies must come from crates.io or approved GitHub organizations
- No wildcard version specifications
- SBOM (CycloneDX format) generated for every release
- Weekly security scans via scheduled CI
- Zero
unwrap()/expect()in library code - Zero
panic!()/todo!()/unimplemented!()in shipped code - All
unsafeblocks require// SAFETY:documentation - Static analysis via Clippy with pedantic lints
Security advisories will be published to:
- GitHub Security Advisories
- The RustSec Advisory Database (for published crates)
- Security issues are fixed with highest priority
- Patches are released as soon as a fix is available
- Public disclosure occurs after patch is available
- Credit is given to reporters (unless anonymity is requested)
- Security issues: Report a vulnerability (private GitHub Security Advisory)
- General issues: GitHub Issues