Reporting a Vulnerability

Please do not report security vulnerabilities in public issues.

Report them privately through GitHub's private vulnerability reporting. Include:

  • the affected version or commit
  • a description of the issue and its impact
  • steps or a proof of concept to reproduce it

We aim to acknowledge reports within 3 business days, and to agree on a disclosure date with the reporter once a fix is available.

Supported Versions

Sovite is pre-1.0. Only the latest release receives security fixes.

Security Model

See docs/security.md for the threat model and the security rules the codebase follows.