Skip to content

Security: Monotox/bvlos-sim

SECURITY.md

Security Policy

Reporting a Vulnerability

If the report contains sensitive details — anything that would hand a working exploit to a reader — use GitHub private vulnerability reporting. It is enabled on this repository, so a private channel always exists and a public issue is never the only option.

For non-sensitive security reports, open a GitHub Issue with reproduction steps, affected versions, and expected impact.

Because this tool parses third-party inputs — fetched GeoJSON, forecast grids, mission and vehicle files authored elsewhere — a crash, hang, or unbounded resource use triggered by a malformed input file is in scope, not just a memory-safety or privilege issue.

CVE Process

bvlos-sim is pre-1.0 and does not yet have a public CVE assignment process. That policy can be revisited after the project has stable release operations.

Safety Disclaimer

bvlos-sim is not a flight-safety system, operational approval tool, or complete BVLOS compliance system. Do not use it as the sole basis for operational BVLOS decisions.

There aren't any published security advisories