verify / verify (push) Successful in 2m55s
Export the reviewed application-neutral package set through the exact public allowlist. Development history and private application evidence remain outside this canonical source root. Developed with material AI assistance under maintainer review. Signed-off-by: Cole Speelman <crspeelman@gmail.com>
17 lines
772 B
Markdown
17 lines
772 B
Markdown
<!-- SPDX-License-Identifier: MPL-2.0 -->
|
|
|
|
# Security policy
|
|
|
|
Report suspected vulnerabilities privately to `security@sandwichhime.com`.
|
|
Include the affected package/version, a minimal reproduction, impact, and any
|
|
suggested mitigation. Please do not place secrets, personal request logs, live
|
|
databases, or exploit details in a public issue.
|
|
|
|
The maintainer aims to acknowledge reports within three business days, provide
|
|
an initial triage within seven, and keep reporters updated at least every
|
|
fourteen days while work remains open. These are best-effort targets, not a
|
|
service-level agreement. There is no bug bounty.
|
|
|
|
The preview supports only versions explicitly listed in release notes. Security
|
|
claims stop at the documented trust boundaries and executable tests.
|