Skip to content

Security: ShardianLabs/EphemeralNet

Security

SECURITY.md

Security Policy

EphemeralNet ships signed release builds through GitHub Releases and is used to handle encrypted, time-bound data. Please follow this policy when reporting security issues.

Supported Versions

The maintainers actively support the latest release tag (v*) and the current master branch. Older releases may not receive patches unless the issue is critical and reproducible on the latest tag.

Reporting a Vulnerability

  1. Do not open a public issue or pull request for security problems.
  2. Submit a private report via the GitHub Security Advisories portal: https://github.com/ShardianLabs/EphemeralNet/security/advisories/new
  3. Include as much detail as possible:
    • Affected EphemeralNet version or commit
    • Reproduction steps or proof-of-concept
    • Impact assessment (confidentiality, integrity, availability)
    • Suggested mitigations if known

If GitHub is unavailable, you may use the "Report content" link on the repository page to reach the administrators.

Response Process

  • You will receive acknowledgement within 3 business days.
  • The maintainers will investigate, develop a fix, and coordinate disclosure.
  • Once a fix is available, we will cut a patched release and credit reporters who wish to be acknowledged.

Thank you for keeping EphemeralNet users safe.

There aren't any published security advisories