Skip to content

Security: pubky/locks

Security

SECURITY.md

Security Policy

Project status

Pubky Locks is pre-production software. Interfaces, persistence formats, and operational assumptions may change without migration support. Do not rely on it to protect valuable private content or real funds without an independent security and operational review.

Reporting a vulnerability

Do not report suspected vulnerabilities, leaked credentials, private identities, recovery material, bearer credentials, or exploit details in a public issue.

Use GitHub's private vulnerability reporting for this repository:

https://github.com/pubky/locks/security/advisories/new

Include the affected revision, impact, reproduction steps, and any suggested mitigation. Minimize sensitive data and use disposable test identities.

If private vulnerability reporting is unavailable, contact a repository maintainer privately and ask for a secure reporting channel before sharing details.

Supported versions

Only the latest revision of the default branch is considered for security fixes. There are no supported releases yet.

Disclosure

Please allow maintainers time to reproduce, remediate, and coordinate disclosure. No response-time or bounty commitment is currently offered.

There aren't any published security advisories