Skip to content

Security: krish567366/submicro-execution-engine

Security

.github/SECURITY.md

Security Policy

Supported Versions

We take security seriously. This section outlines which versions of our project are currently supported with security updates.

Version Supported
2.1.x
2.0.x
< 2.0

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it responsibly. We appreciate your help in keeping our users safe.

How to Report

Please do NOT report security vulnerabilities through public GitHub issues.

Instead, please report security vulnerabilities by emailing:

What to Include

When reporting a vulnerability, please include:

  1. Description: A clear description of the vulnerability
  2. Impact: What an attacker could achieve by exploiting this vulnerability
  3. Steps to Reproduce: Detailed steps to reproduce the issue
  4. Proof of Concept: If possible, include a proof of concept
  5. Environment: Your testing environment (OS, versions, etc.)
  6. Suggested Fix: If you have suggestions for fixing the issue

Our Response Process

  1. Acknowledgment: We will acknowledge receipt of your report within 48 hours
  2. Investigation: We will investigate the report and determine its validity
  3. Updates: We will provide regular updates on our progress (at least weekly)
  4. Fix Development: If valid, we will develop and test a fix
  5. Disclosure: We will coordinate disclosure with you

Disclosure Policy

  • We follow responsible disclosure practices
  • We will credit you (if desired) in our security advisory
  • We aim to release fixes as quickly as possible
  • We will not disclose vulnerability details until a fix is available

Scope

This security policy applies to:

  • The SubMicro Execution Engine core codebase
  • Official documentation
  • Official build scripts and tooling

Out of Scope

This policy does not apply to:

  • Third-party dependencies (report to the respective projects)
  • Configuration issues in user environments
  • Denial of service attacks that require unrealistic resource usage
  • Issues in development/unreleased code

Safe Harbor

We consider security research conducted in accordance with this policy to be authorized research. We will not pursue legal action against researchers who follow this policy.

Security Updates

Security updates will be released as patch versions with the following naming convention:

  • MAJOR.MINOR.PATCH where PATCH indicates a security fix

Security advisories will be published on:

Contact

For security-related questions or concerns:

Thank you for helping keep the SubMicro Execution Engine secure!

There aren’t any published security advisories