BetaPublic beta — Read the release notes

Security Policy

Effective date: 2025-01-01 Canonical domain: solidiom.org

Supported Versions

VersionSupported
Latest next prereleaseYes
Previous next prereleaseBest effort
Stable releases (when available)Yes

Reporting a Vulnerability

We use GitHub Private Vulnerability Reporting for coordinated disclosure.

When you submit a report:

  1. You’ll receive an acknowledgment within 48 hours
  2. We’ll confirm the vulnerability’s validity within one week
  3. We’ll communicate the mitigation timeline
  4. You’ll be credited in the advisory unless you request anonymity

What to Include

What We Don’t Accept

Scope

This policy covers:

Coordinated Disclosure

We follow a coordinated disclosure process:

  1. Report — submit via GitHub Private Vulnerability Reporting
  2. Triage — we assess severity and scope within 7 days
  3. Fix — we develop and test a patch
  4. Release — we publish the fix and a security advisory
  5. Credit — we acknowledge the reporter (unless anonymity is requested)

Target timelines:

Registry Integrity

The registry uses Ed25519 asymmetric signatures for manifest integrity. If you discover a signature verification failure or a potential key compromise, report it as a Critical severity vulnerability.