Skip to content

Security: jscott3201/rusty-bacnet

Security

.github/SECURITY.md

Security Policy

Supported Versions

Before 1.0, security fixes land on dev and ship in the next release, which may be a new minor version (for example 0.12.0). Fixes aren't backported to older release lines, so upgrade to the latest release to receive them.

Version Supported
dev branch ✅
Latest release (currently 0.11.x) ✅
Older releases ❌

Reporting a Vulnerability

If you discover a security vulnerability in rusty-bacnet, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

Instead, please email jscott3201@gmail.com with:

  • A description of the vulnerability
  • Steps to reproduce the issue
  • The affected version(s)
  • Any potential impact assessment

You should receive an acknowledgment within 48 hours. We will work with you to understand the issue and coordinate a fix and disclosure timeline.

Scope

This policy covers:

  • The Rust crates in this repository (bacnet-types, bacnet-encoding, bacnet-services, bacnet-transport, bacnet-network, bacnet-objects, bacnet-client, bacnet-server, bacnet-endpoint-core, bacnet-endpoint)
  • The bacnet CLI (bacnet-cli)
  • The Python bindings (rusty-bacnet)
  • BACnet protocol handling (parsing, encoding, transport security)

Security issues in the BACnet/SC TLS implementation, authentication bypasses, buffer overflows in protocol decoding, and denial-of-service vectors in transport/network layers are of particular interest.

There aren't any published security advisories