Skip to content

Security: SwuduSusuwu/SubStack

SECURITY.md

Security Policy

Asof 2024 December 24, all commit signatures shall match ./.ssh/sha256.sig values. ./README.md#Signaturecertificate shows how to test this on your own.

Supported versions

Users can expect that past 2024 June 26, trunk passes susuwuUnitTests(), which uses Susuwu::unitTestsCxx()1 + GitHub's code scans2.

Sensitive issues

First, view How to contribute for information on issues (to ensure that what you found is not a normal issue).

If you found normal issue(s), such as this, use this normal route to post about new issues.

But if you found sensitive issue(s), such as this, you have a few options to report the issue:

You can expect:

  • Best effort to address the issue(s),
  • with you anonymous (unless you ask to publish credits to you.)

Errata/footnotes

Footnotes

  1. Asof commmit 7a9f52b2301f16807485b6701bec883404b4bd29 (+cxx/main.hxx: for issues #3, #14: cross-language), testHarnesses is now susuwuUnitTests.

  2. Asof commmit 36fa8a54a2a56d6e5bf21899980b48b462c15bde (+.github/workflows/codacy.yml New GitHub analysis.), the code scans now include all of Codacy's test results; before this, just GitHub's CodeQL produced code scans.

There aren’t any published security advisories