Skip to content

Security: iamseth/yin

Security

SECURITY.md

Security policy

yin is experimental, pre-1.0 software. It does not yet have long-term support releases or a guaranteed security-fix or backport window. Security fixes will target the current code and the latest released v0.x line when practical; users should expect to upgrade to receive fixes.

Reporting a vulnerability

Do not disclose suspected vulnerabilities in a public issue, discussion, or pull request. Use GitHub Private Vulnerability Reporting through the repository's Report a vulnerability form instead. Include affected versions, impact, reproduction details, and any suggested mitigation when available.

Maintainers will acknowledge the report, investigate it, and coordinate disclosure and a fix as circumstances permit. Because the project is experimental and maintained on a best-effort basis, no response or remediation deadline is guaranteed.

There aren't any published security advisories