This is the default security policy for repositories in the provin-line
organization. A repository's own SECURITY.md, where present, takes
precedence.
The provin / dPLaaX stack is a proof-of-concept. It is not a hardened production system. We nonetheless take vulnerability reports seriously and will assess every one.
Please do not open a public issue for a suspected vulnerability. Public disclosure of an unpatched flaw puts every deployment at risk.
Report privately through GitHub Private Vulnerability Reporting on the affected repository: the Security tab → Report a vulnerability. This opens a private advisory visible only to you and the maintainers. If the Security tab is unavailable, email yoshi@1o1.co.jp instead.
Please include, to the extent you can:
- affected repository and version or commit,
- impact (what an attacker gains),
- reproduction steps or a proof of concept,
- any embargo/disclosure timing you would like us to honor.
We do not commit to an acknowledgement or remediation SLA, and we do not operate a bug-bounty program. We will engage on the private advisory and coordinate disclosure with you.