Skip to content

Latest commit

 

History

History
34 lines (21 loc) · 1.31 KB

File metadata and controls

34 lines (21 loc) · 1.31 KB

Security Policy

Reporting a vulnerability

If you discover a security vulnerability in this project, please report it through GitHub Security Advisories. This ensures your report is handled privately and responsibly.

Do not open a public issue for security vulnerabilities.

What to include

When reporting a vulnerability, please provide:

  • A clear description of the issue.
  • Steps to reproduce the vulnerability, if applicable.
  • The affected files, schemas, or components.
  • The potential impact (e.g. data exposure, schema bypass, trust model weakness).

What counts as a security issue

In the context of this project, security issues may include:

  • Schema design flaws that could allow invalid or malicious data to pass validation.
  • Issues that could undermine the trust model or integrity of credential data.
  • Exposure of sensitive information through sample data or documentation.

Response process

  • We aim to acknowledge reports within 5 working days.
  • We will work with you to understand and validate the issue.
  • Fixes will be applied to the main branch. There is no backporting to previous versions.

Supported versions

Only the latest version on the main branch is actively maintained.