Skip to content

Security: SamMausberg/KernelIndex

Security

SECURITY.md

Security policy

Supported: the main branch and the production site (kernelindex.com), including /api/v1 and the packages in this repository.

Reporting. Use GitHub private vulnerability reporting on this repository ("Report a vulnerability" under the Security tab). Do not open public issues for exploitable findings. Expect acknowledgment within 72 hours, triage within a week, and coordinated disclosure within 90 days of report.

Scope. kernelindex.com, /api/v1, the importers, and authentication. KernelIndex has no user-code execution surface: anything that appears to execute submitted code is itself a critical finding.

Safe harbor. Good-faith research against your own accounts and data is welcome. Prohibited: destructive testing, mutating or deleting catalog data, load/DoS testing, and access to other users' data beyond the minimum proof needed.

Acknowledgment. Reporters are credited in release notes on request. There is no bounty program at this time.

There aren't any published security advisories