Skip to content

Security: rengwu/chartr

SECURITY.md

Security

Reporting a vulnerability

Report it privately, not as a public issue:

Whatever you can share helps: the version or commit, what an attacker gets, and the shortest path you know to reproduce it. A rough description is worth reporting — a polished writeup is appreciated but not required.

What to expect

chartr is a one-maintainer alpha project, so this is a promise about conduct, not a service level:

  • An acknowledgement, normally within a few days.
  • An honest answer on whether it is a bug, and if so what the fix looks like and roughly when — including "not soon", if that is the truth.
  • Fixes land on main and in the next release. There is no back-porting to older tags.
  • You will be credited in the release notes and in any advisory, under whatever name you give, unless you ask not to be.

There is no bug bounty at this stage, sorry.

There aren't any published security advisories