Skip to content

Security: noCharger/kernel-factory

Security

SECURITY.md

Security policy

Supported versions

Security fixes are currently made on the latest revision of the main branch. The project is pre-1.0, so downstream users should pin an exact revision and review changes before deployment.

Reporting a vulnerability

Please use the repository host's private security-advisory feature. Do not open a public issue for vulnerabilities, leaked credentials, or reports containing sensitive target-machine details. If private reporting is unavailable, contact a maintainer through an established private channel before sharing details.

Include the affected revision, impact, reproduction steps, and any proposed mitigation. Maintainers should acknowledge a complete report within seven days and coordinate disclosure after a fix is available.

Trust boundary

Candidate and policy output is untrusted. It must not bypass the fixed-command compiler adapter, isolated correctness oracle, safety pipeline, benchmark promotion rules, content-addressed evidence store, or independent release qualification. Reports that cross this boundary, permit shell-command injection, mutate oracle truth, forge hardware origin, or weaken fail-closed stage ordering are considered security-sensitive.

There aren't any published security advisories