Please do not open a public issue for security problems.
Instead, use GitHub's private vulnerability reporting: Security → Report a vulnerability on the repository page.
You should receive an acknowledgment within a few days. Please include steps to reproduce and the affected version/commit.
Diskern touches user files, so we treat the following as security issues:
- Anything that causes a scan (which must be read-only) to modify files.
- Anything that bypasses quarantine and hard-deletes data.
- Path traversal or symlink tricks that let a rule act outside scanned roots.
- The updater accepting an improperly signed release.
Only the latest release receives security fixes.