EphemeralNet ships signed release builds through GitHub Releases and is used to handle encrypted, time-bound data. Please follow this policy when reporting security issues.
The maintainers actively support the latest release tag (v*) and the current master branch. Older releases may not receive patches unless the issue is critical and reproducible on the latest tag.
- Do not open a public issue or pull request for security problems.
- Submit a private report via the GitHub Security Advisories portal: https://github.com/ShardianLabs/EphemeralNet/security/advisories/new
- Include as much detail as possible:
- Affected EphemeralNet version or commit
- Reproduction steps or proof-of-concept
- Impact assessment (confidentiality, integrity, availability)
- Suggested mitigations if known
If GitHub is unavailable, you may use the "Report content" link on the repository page to reach the administrators.
- You will receive acknowledgement within 3 business days.
- The maintainers will investigate, develop a fix, and coordinate disclosure.
- Once a fix is available, we will cut a patched release and credit reporters who wish to be acknowledged.
Thank you for keeping EphemeralNet users safe.