Skip to content

Security: askq-git/kori

Security

SECURITY.md

Security Policy

Supported versions

Security fixes are currently provided for the latest published Kori beta. Older development builds may be asked to upgrade before a report is investigated.

Reporting a vulnerability

Please do not disclose a suspected vulnerability in a public issue.

Email kori.dev@askq.co.nz with the subject Private security report: Kori. Do not open a public issue containing security-sensitive details.

Include the Kori, OBS and Windows versions, reproduction steps, the potential impact and any suggested mitigation.

Reports will be acknowledged as soon as practical. A fix and disclosure timeline will be agreed privately after the issue is reproduced.

Package trust

Official Kori packages are published only through this repository's GitHub Releases page. Beta installers are not yet code-signed. Compare the downloaded ZIP's SHA-256 digest with the checksum shown in its release before installing.

There aren't any published security advisories