Skip to content

Security: mapleleaflatte03/meridian

Security

SECURITY.md

Security Policy

Supported Scope

Security reports should target the canonical monorepo:

Archived mirrors are read-only and should not be used for new security reporting.

Private Disclosure

Use GitHub private vulnerability reporting:

Do not open public issues for exploitable vulnerabilities before maintainers triage and patch.

What to Include

  1. Affected module(s): loom/, kernel/, intelligence/
  2. Reproducible steps and minimal payload
  3. Impact assessment (confidentiality/integrity/availability)
  4. Suggested mitigation or hardening idea (if available)

Response Expectations

  • Initial acknowledgment target: 72 hours
  • Triage status update target: 7 days
  • Public disclosure only after patch or explicit maintainer approval

There aren't any published security advisories