Do not open a public issue for security vulnerabilities.
Please report vulnerabilities by email to Atelier Socle Contact. Include:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- 48 hours: Initial acknowledgment
- 7 days: Triage and severity assessment
- 30 days: Fix developed and tested
- Coordinated disclosure: Public advisory after the fix is released
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
| < 0.1 | ❌ |
This policy covers the swift-cmaf-kit Swift package, including the CMAFKit library and cmafkit-cli CLI tool.