Skip to content

Security: CarlSR9001/whetstone

SECURITY.md

Security policy

Supported versions

Security fixes are made on the latest released minor version and on main. Older releases may be affected even when a fix is straightforward to backport.

Reporting a vulnerability

Please use GitHub's private vulnerability-reporting form:

https://github.com/CarlSR9001/whetstone/security/advisories/new

Do not open a public issue for an unpatched vulnerability and do not include private exam-bank contents, submitted answers, service credentials, or signing keys in a report. Include the affected version or commit, a minimal reproduction, the security boundary that was crossed, and any known impact.

You should receive an acknowledgement within seven days. A fix timeline depends on severity and whether coordinated disclosure is needed. Credit is offered in the release notes unless you prefer to remain anonymous.

Public-service boundary

The hosted workbench intentionally loads no private promotion bank. Disposable report-card prompts are public practice material, and Open Promotion Bench system identities are self-attested. Those boundaries are security-relevant: please report any path that exposes persistent private-bank data, raw submitted answers, service credentials, signing keys, or cross-session task material.

There aren't any published security advisories