This is the organisation-wide fallback. A repository that ships its own SECURITY.md overrides
it — see ctrlrun's policy for the
release provenance, attestation and signing details specific to that project.
Report vulnerabilities privately to contact@arpanghoshal.com. Please do not open a public issue for a security report.
Include what you need to make the problem reproducible: the version, the policy file, and the sequence of actions. A failing test is the fastest possible report.
Expect an acknowledgement within 72 hours and an assessment within seven days. If a fix is warranted you will be credited in the release notes unless you ask not to be.
We are most interested in anything that lets a consequential action happen more than once, happen differently from how it was approved, or happen without leaving a receipt — and in anything that turns an outcome the code cannot observe into a definite one.