| Version | Supported |
|---|---|
0.1.x | Yes |
Do not open public GitHub issues for security-sensitive reports.
- Email or DM maintainers with: version, OS build, reproduction steps, impact.
- Include
golden-verify.ps1/verify.ps1output when relevant. - Allow reasonable time for patch before disclosure.
In scope:
soren-crypto,soren-vfs,soren-corememory safety and crypto logic- FFI boundary (
soren.dll,include/soren.h) - WinUI/Flutter shells only where they expose key material or mount points
Out of scope:
- Third-party tools (WinFsp, Flutter SDK) unless integration bug in Soren
Persian: SECURITY.fa.md