Security Policy

Reporting a Vulnerability

Do not create public GitHub issues for security vulnerabilities.

Primary: GitHub Security Advisories (Preferred)

Report a vulnerability via GitHub Security Advisories

This ensures your report is kept confidential until a fix is released.

Email

For questions or if GitHub Advisories is unavailable:

[email protected]

Response Timeline

SeverityAcknowledgmentPatch Target
Critical48 hours30 days
High48 hours30 days
Medium7 days90 days
Low30 daysBest effort

Supported Versions

Only the latest release on crates.io receives security patches.

Disclosure Policy

We follow coordinated disclosure:

  1. You report the vulnerability privately
  2. We acknowledge within 48 hours
  3. We develop and test a fix
  4. We release the fix and publish a security advisory
  5. You may publicly disclose after the fix is released

Credits

We publicly credit reporters in the security advisory unless anonymity is requested.

Thank you for helping keep Reinhardt secure.