Supported: the main branch and the production site (kernelindex.com),
including /api/v1 and the packages in this repository.
Reporting. Use GitHub private vulnerability reporting on this repository ("Report a vulnerability" under the Security tab). Do not open public issues for exploitable findings. Expect acknowledgment within 72 hours, triage within a week, and coordinated disclosure within 90 days of report.
Scope. kernelindex.com, /api/v1, the importers, and authentication.
KernelIndex has no user-code execution surface: anything that appears to
execute submitted code is itself a critical finding.
Safe harbor. Good-faith research against your own accounts and data is welcome. Prohibited: destructive testing, mutating or deleting catalog data, load/DoS testing, and access to other users' data beyond the minimum proof needed.
Acknowledgment. Reporters are credited in release notes on request. There is no bounty program at this time.