KNF / public recordSecurity / Disclosure
Responsible disclosure

A responsible path for vulnerability reports.

The disclosure policy is structured for review before publication. Do not send sensitive security details through an unverified channel.

The final policy will define scope, report contents, safe-harbor language, coordinated disclosure, acknowledgement, and communication expectations.

Until an official channel is published, use the security process documented in the relevant public repository and avoid filing sensitive detail through general contact forms.

Report

Include reproducible detail.

Impact, affected versions, reproduction steps, and proposed mitigations.

Coordinate

Make room for remediation.

Embargoes and timelines should be discussed with affected maintainers.

Acknowledge

Credit responsible research.

Security contributors should receive appropriate acknowledgement when safe.

IndexStatus / scope
ScopeTo be defined
ChannelNot yet published
Safe harborLegal review required
DisclosureCoordinated process