Skip to content

Security: Ali-Rashidi-80/Soren

Security

SECURITY.md

Security Policy

Supported versions

VersionSupported
0.1.xYes

Reporting a vulnerability

Do not open public GitHub issues for security-sensitive reports.

  1. Email or DM maintainers with: version, OS build, reproduction steps, impact.
  2. Include golden-verify.ps1 / verify.ps1 output when relevant.
  3. Allow reasonable time for patch before disclosure.

Scope

In scope:

  • soren-crypto, soren-vfs, soren-core memory safety and crypto logic
  • FFI boundary (soren.dll, include/soren.h)
  • WinUI/Flutter shells only where they expose key material or mount points

Out of scope:

  • Third-party tools (WinFsp, Flutter SDK) unless integration bug in Soren

Hardening references

Persian: SECURITY.fa.md

There aren't any published security advisories