Skip to content

Security: symbolicsoft/hpke-ng

SECURITY.md

Security Policy

Supported Versions

Only the latest release on the main branch is supported. Users should always update to the latest version.

Reporting a Vulnerability

If you discover a security vulnerability in hpke-ng, you are welcome to report it by opening a GitHub issue or submitting a pull request with a fix. There is no requirement for coordinated or private disclosure — use whichever method you prefer.

Please include:

  • A description of the vulnerability and its potential impact.
  • Steps to reproduce the issue, or a proof of concept if applicable.
  • A tested, complete fix, if possible.

Disclaimer

Extensive effort has been undertaken to ensure the correctness, interoperability, safety and reliability of this library. While it is likely ready for production use, it is offered as-is and without a guarantee.

There aren't any published security advisories