Skip to content

Security: wavect/semaprax

Security

SECURITY.md

Security policy

SEMAPRAX is pre-alpha and is not suitable for production or safety-critical software. Security properties in an RFC are design requirements unless the completion matrix links them to qualifying executable evidence. A private or proof-only host fixture is not a supported security boundary.

Report vulnerabilities privately through GitHub's security advisory feature for wavect/semaprax. Do not open a public issue for an undisclosed vulnerability.

Include the affected commit, host platform, minimal source or patch input, observed impact, and reproduction steps. Maintainers will acknowledge a complete report as soon as practical and coordinate disclosure after a fix is available.

There aren't any published security advisories