Skip to content

Security: ip332/quarry

Security

SECURITY.md

Security policy

Quarry follows the supported release line documented in the repository. Users should keep the compiler and runtimes from the same compatible release, using the generated-code API checks where applicable.

Reporting a vulnerability

Please report suspected security vulnerabilities privately through GitHub's private vulnerability reporting or security advisory mechanism for this repository. If that mechanism is unavailable, contact the repository maintainers privately through the GitHub account rather than opening a public issue.

Include the affected version, platform, reproduction steps, and any minimal proof of concept that can be shared safely. Do not disclose the vulnerability publicly until the maintainers have acknowledged it and coordinated a response.

The maintainers will review the report, confirm the affected scope, coordinate any fix or mitigation, and communicate the publication plan. Response timing depends on severity, maintainer availability, and the complexity of the issue.

There aren't any published security advisories