hood is highly experimental. Until the first stable release, only the current
main branch and the newest prerelease receive security fixes.
Do not open a public issue for a suspected vulnerability. Use GitHub private vulnerability reporting and include:
- affected commit or version;
- reproduction steps or a proof of concept;
- impact and realistic attack conditions;
- any proposed mitigation.
The maintainers aim to acknowledge complete reports within three business days. This is a best-effort target, not a service-level agreement. We will coordinate validation, remediation, and disclosure with the reporter.
Security boundaries and known gaps are summarized in the README. Bypasses already
documented there are not vulnerabilities unless they cross a boundary that hood
claims to enforce.