Skip to content

Security: andrebuilds/trosive

Security

SECURITY.md

Security Policy

Supported versions

Trosive is in early development and has not published a stable release. Security fixes are applied only to the latest code on the master branch.

Version Supported
Latest master Yes
Older commits or prereleases No

Reporting a vulnerability

Do not report security vulnerabilities in public issues, discussions, or pull requests.

Use GitHub private vulnerability reporting to submit a report. If private reporting is unavailable, contact the maintainer privately through a contact method listed on @andrebuilds' GitHub profile.

Include the following information when possible:

  • A clear description of the vulnerability and its impact
  • The affected route, component, dependency, or commit
  • Reproduction steps or a minimal proof of concept
  • Any preconditions required for exploitation
  • A suggested remediation, if known

Never include credentials, API keys, personal data, or confidential documents in a report. Use synthetic or fully redacted examples.

The maintainer aims to acknowledge complete reports within seven days. Fix and disclosure timelines depend on severity and complexity. Please allow reasonable time for remediation before publishing details.

Incorrect AI output without a confidentiality, integrity, or availability impact should be reported as a regular bug rather than a security vulnerability.

There aren't any published security advisories