Files
wickra/SECURITY.md
T
kingchenc f7b91f6fa5 chore: use support@wickra.org for contact/author email; drop dead sponsor link (#97)
Now that the wickra.org catch-all mailbox exists, move the project contact +
package-author email off the personal gmail to support@wickra.org across all
surfaces: CODE_OF_CONDUCT, SECURITY, CITATION.cff, Cargo.toml, the npm + PyPI
author fields, the release.yml npm author, and repo-metadata.toml. (The
package-author changes take effect on the next published release.)

repo-metadata.toml's [audit].forbidden still pins kingchencp@gmail.com (the
private commit email) as a banned substring — unchanged.

Also remove the FUNDING.yml custom "https://wickra.org/sponsor" entry: that
page 404s, so the Sponsor button linked to a dead URL. The GitHub Sponsors
entry (github: [kingchenc]) stays.
2026-05-31 23:22:57 +02:00

1.4 KiB

Security Policy

Supported versions

Wickra is pre-1.0. Security fixes are applied to the latest released 0.1.x version only; please upgrade to the newest release before reporting an issue.

Version Supported
0.1.x (latest)
older 0.1.x

Reporting a vulnerability

Do not open a public issue for a security vulnerability.

Report it privately through one of:

Please include:

  • the affected version(s) and platform / language binding,
  • a description of the issue and its impact,
  • steps to reproduce, ideally a minimal proof of concept.

What to expect

  • An acknowledgement within 5 working days.
  • An assessment and, if confirmed, a planned fix with a target release.
  • Coordinated disclosure: we will agree on a disclosure date with you and credit you in the release notes unless you prefer to stay anonymous.

Scope

In scope: the published crates (wickra-core, wickra-data, wickra), the PyPI/npm packages, and the build/release workflows in .github/workflows/.

Out of scope: vulnerabilities in third-party dependencies (report those upstream; we track them via Dependabot and cargo-deny).