Trosive is in early development and has not published a stable release. Security
fixes are applied only to the latest code on the master branch.
| Version | Supported |
|---|---|
Latest master |
Yes |
| Older commits or prereleases | No |
Do not report security vulnerabilities in public issues, discussions, or pull requests.
Use GitHub private vulnerability reporting to submit a report. If private reporting is unavailable, contact the maintainer privately through a contact method listed on @andrebuilds' GitHub profile.
Include the following information when possible:
- A clear description of the vulnerability and its impact
- The affected route, component, dependency, or commit
- Reproduction steps or a minimal proof of concept
- Any preconditions required for exploitation
- A suggested remediation, if known
Never include credentials, API keys, personal data, or confidential documents in a report. Use synthetic or fully redacted examples.
The maintainer aims to acknowledge complete reports within seven days. Fix and disclosure timelines depend on severity and complexity. Please allow reasonable time for remediation before publishing details.
Incorrect AI output without a confidentiality, integrity, or availability impact should be reported as a regular bug rather than a security vulnerability.