Skip to content

Security: Rick1330/ibex-harness

.github/SECURITY.md

Security Policy

Reporting a vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Report privately using GitHub Private vulnerability reporting (Security Advisories):

  1. Open the repository Security tab.
  2. Choose Report a vulnerability, or go directly to Report a vulnerability.

Repository maintainers must enable Private vulnerability reporting under Settings → Security → Code security and analysis if the option is not visible.

Include: description, impact, reproduction steps, and affected components if known.

Full security documentation

Threat model, invariants, and engineering controls are documented in:

Response expectations

We aim to acknowledge reports within 5 business days. Critical issues affecting tenant isolation or secrets will be prioritized.

There aren't any published security advisories