This project is pre-release (0.x.x). Until a 1.0 release, only the latest commit on the main branch receives security fixes.
Please report suspected vulnerabilities privately through GitHub's private vulnerability reporting on this repository: open the Security tab and click Report a vulnerability. Do not open a public issue, pull request, or discussion for a security report.
When reporting, please include:
- a description of the issue and its impact,
- the affected component or crate,
- a minimal reproduction, if possible.
We aim to acknowledge reports within three business days and to share a remediation timeline after triage.
This stack implements cryptographic and networking protocols. Reports about the engine's handling of untrusted wire input, key material, or entropy are especially welcome.