Skip to content

Security: nimbus-agent/Nimbus

.github/SECURITY.md

Security Policy

Nimbus takes security seriously. The full security model, threat model, and invariant catalogue (I1–I30, with I28 reserved) live in docs/SECURITY.md and the central nimbus-security repository.

Reporting a vulnerability

Please do not open a public issue for security reports.

Use GitHub's private vulnerability reporting — the Security tab → Report a vulnerability. It is the only reporting channel: Nimbus publishes no security email address and no PGP key, because a solo maintainer's unmonitored inbox drops reports silently.

Nimbus is maintained by one person as a side project, so there is no guaranteed response time and no SLA. Reports are typically read within a week and prioritised by severity, and we will agree a coordinated-disclosure timeline with you. See the full policy, scope and safe-harbor terms in nimbus-security.

There aren't any published security advisories