Taintkit is a security control; we take bugs in it seriously.
Please do not open public issues for security vulnerabilities. Instead, use GitHub's private vulnerability reporting ("Report a vulnerability" under the Security tab) or email admin@nintech.io.
We aim to acknowledge reports within 3 business days.
- A flow that a policy is documented as covering, but which the engine allows, is a policy accuracy issue if it depends on paraphrases the session tracker cannot see. Open a normal issue. Containment matching is a safety net, not a parser.
- The engine allowing a labeled untrusted value into a matching sink, schema confusion, or the SDK crashing an application on untrusted input are vulnerabilities.
Only the latest minor release receives security fixes.