Security fixes are provided for the latest published KSafe release line on Maven Central. Users on older versions may be asked to upgrade to a fixed release.
Please do not report suspected security vulnerabilities in public GitHub issues.
Use GitHub's private vulnerability reporting for this repository: https://github.com/ioannisa/KSafe/security/advisories/new. If that is unavailable, contact the maintainer at ioannisanif@gmail.com.
A useful report includes:
- Affected KSafe version.
- Affected platform(s).
- Reproduction steps or proof of concept.
- Expected impact.
- Suggested mitigation, if known.
The maintainer will review reports as promptly as possible and coordinate disclosure once a fix or mitigation is available.
For KSafe's encryption design, runtime security policy, threat model, and platform key-custody details, see docs/SECURITY_MODEL.md.