We take security seriously.
- Please report vulnerabilities privately.
- Do not open public Issues for security reports.
Preferred (fastest):
If the above is not available, email the maintainer privately: comstrx@gmail.com
✅ Security reports include:
- remote code execution, auth bypass, data exposure, privilege escalation
- supply-chain or verification issues with clear impact
- unsafe defaults that affect real deployments
❌ Not security reports (use Issues/Discussions instead):
- general bugs, feature requests, usage questions -> Issues / Discussions
- crashes without security impact details
- affected crate(s) + the commit or tag you are on
- impact (what can an attacker do?) + assumptions / threat model
- minimal reproduction or PoC (safe and small)
- environment details (OS/arch,
rustc --version) - relevant logs / error output
🚫 Do not include secrets (tokens, private keys, credentials, personal data).
- Please avoid public disclosure until a fix is available.
- We will coordinate on a timeline, patch, and advisory when confirmed.
- When appropriate, we disclose via releases and ecosystem advisories (e.g., RustSec).