Skip to content

Security: reasvyn/rvlibs

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in any rvlibs crate, please do not open a public issue. Instead, send a private report via one of the following channels:

You should receive a response within 48 hours. If you do not hear back, follow up via email to ensure the message was received.

What to Include

  • A clear description of the vulnerability
  • Steps to reproduce (proof of concept)
  • Potential impact
  • Any suggested fix (if available)

Scope

  • Code execution vulnerabilities in rvlibs crates
  • Unsafe code blocks that could be exploited
  • Dependency vulnerabilities with active exploits

Policy

  • We will acknowledge receipt within 48 hours
  • We will provide an estimated timeline for a fix
  • We will credit the reporter in the release notes (unless anonymity is requested)
  • We will publish a security advisory after the fix is released

Supported Versions

Version Supported
0.x

There aren't any published security advisories