If you discover a security vulnerability or a critical crash within Galadril, please do not open a public GitHub issue. Instead, please report it privately to ensure we can fix it before it becomes public knowledge.
The preferred reporting channel is to open a GitHub Security Advisory. This allows you to safely disclose the details, and allows us to collaborate on a fix in a private fork.
Alternatively, you can reach out directly via email at: aeluin@gravitalia.com
Thank you for helping keep Galadril secure during its early stages!
As Galadril is currently in active early development, security fixes are only
provided for the latest state of the repository (main branch).
| Version | Supported |
|---|---|
| main | ✅ Yes |
| < main | ❌ No |
- Acknowledgment: We will acknowledge receipt of your vulnerability report within 2 business days.
- Fix Development: A fix will be developed privately. If reported via GitHub Advisories, you can be added to the private space to collaborate or review the patch.
- Release & CVE: Once the fix is ready, it will be merged into the
mainbranch. A public Security Advisory will be published, and a CVE will be requested if applicable to notify the community.