Skip to content

Security: rekurt/gost-crypto

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
latest

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it responsibly.

Do not open a public issue.

Instead, use one of the following methods:

  1. GitHub Security Advisories: Open a private security advisory at https://github.com/rekurt/gost-crypto/security/advisories/new

  2. Email: Send details to the repository maintainer (see profile).

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgement: within 3 business days
  • Initial assessment: within 7 business days
  • Fix release: depends on severity, typically within 30 days

Disclosure

We follow coordinated disclosure. Please allow time for a fix before public disclosure.

Threat Model

For detailed threat model, security assumptions, and known limitations, see docs/THREAT_MODEL.md.

There aren't any published security advisories