Report vulnerabilities privately to security@granularity.tech.
Please do not open a public issue: a public report is a public exploit until the fix ships.
| Step | Commitment |
|---|---|
| Acknowledgement | Within 72 hours |
| Assessment of severity | With the acknowledgement or shortly after |
| Fix and release | Out of band — security fixes do not wait for the next planned release |
| Backport | To the previous major, within its support window |
| Advisory | GitHub Security Advisory, with a CVE where one applies |
| Credit | Your name in the advisory, unless you would rather not be named |
There is no bounty programme. This is stated plainly rather than left to be discovered after the work is done.
Full policy: https://granularity.tech/legal/security Machine-readable: https://granularity.tech/.well-known/security.txt