Skip to content

Security: firestoned/sceau

Security

SECURITY.md

Security Policy

Supported Versions

sceau is pre-1.0 and under active development. Only the latest commit on main and the most recent release receive security fixes.

Version Supported
latest release / main ✅
anything older ❌

Reporting a Vulnerability

Do not open a public issue for a suspected vulnerability.

Report it privately via GitHub's private vulnerability reporting ("Report a vulnerability" on the repository's Security tab).

Include, where possible:

  • the affected component (KMS service, TPM sealing, deployment unit) and version/commit;
  • steps to reproduce or a proof of concept;
  • the impact you believe it has.

You can expect an acknowledgement within 3 business days and a triage decision (accepted / needs-more-info / not-a-vulnerability) within 7. Accepted reports get a fix or mitigation plan, and credit in the release notes unless you ask otherwise.

Scope Notes

  • The intended deployment trust model is documented in README.md and ADR-0001 — issues that require already-root access on the host are generally out of scope (the KMS socket is mode 0600 precisely because root is the trust boundary).
  • Supply-chain controls (SBOM, Cosign signing, Trivy scanning) are described in ADR-0002; the dependency policy lives in deny.toml.

There aren't any published security advisories