This is the org-wide baseline security policy for kaappi/* repositories. A
repo with its own threat model or attack surface (e.g. the core interpreter's
sandbox and FFI trust boundary) documents that separately in its own
SECURITY.md, in addition to the sections below.
Only the latest release on main is supported with security fixes. There are
no long-term-support branches at this time.
Do not open a public issue for security vulnerabilities.
Use GitHub's private security advisory feature on the affected repo (Security tab → "Report a vulnerability") to report vulnerabilities. You will receive an acknowledgment within 72 hours and a substantive response within 14 days.
If you cannot use GitHub advisories, email a maintainer directly — see MAINTAINERS.md.
This policy covers all repositories under the kaappi GitHub org.