Skip to content

Security: kyaulabs/prism

SECURITY.md

Security Policy

Supported versions

Prism remains pre-1.0.

Version Supported
<1.0.0 Yes
>=1.0.0 No

Report a vulnerability

Email security reports to git@kyaulabs.com.

Do not open a public issue for a suspected vulnerability. Do not include API keys, tokens, passwords, private keys, environment files, exploit data, or other credentials in GitHub issues, pull requests, discussions, logs, or agent context.

Include:

  • the affected Prism version or commit;
  • the affected package or component;
  • reproduction steps or a minimal proof of concept;
  • the expected and observed security boundary;
  • known impact and mitigations;
  • a safe way to contact you.

Report vulnerabilities in third-party dependencies to their maintainers as well as to Prism when Prism's use of the dependency creates an exploitable condition.

Disclosure process

The maintainer will acknowledge the report within 48 hours and provide an initial handling response within another 48 hours when possible. The handler will confirm the issue, identify affected versions, check for related defects, prepare fixes for supported versions, and coordinate release and disclosure.

Keep the report private until the maintainer confirms that a fix and disclosure are ready. Credit is optional and follows the reporter's preference.

There aren't any published security advisories