Skip to content

Security: acgetchell/CDT-plusplus

SECURITY.md

Security and support

CDT++ v1.0.0 is a historical scientific reference scheduled for archival after a maintenance-only stabilization window. No CDT++ version receives active feature development or guaranteed security maintenance, and fixes to this archive are not guaranteed.

For a vulnerability, correctness defect, or support request that affects the active implementation, report it to causal-triangulations through that repository's current reporting guidance.

For a vulnerability specific to the CDT++ code, do not publish sensitive details in a public issue. Contact the repository owner through a private channel identified on that GitHub profile, using the subject CDT++ security report and including the affected revision or release, a minimal reproducer when safe, and an assessment of impact. Reports may be documented for historical users, but the archive does not promise a patch or new release.

Ordinary usage questions, feature requests, and new scientific work belong in the successor repository. The historical CDT++ issue tracker remains available during stabilization and will become read-only when issue #155 eventually completes the archival sequence.

There aren't any published security advisories