Skip to content

Security: bootlace-dev/supercala

Security

SECURITY.md

Security Policy

Supported Versions

Only the master branch receives active security updates.

VersionSupported
master

Reporting a Vulnerability

We take the security of high-assurance financial infrastructure seriously.

If you discover a potential vulnerability, deadlock cycle, cryptographic edge case, or invariant violation in SuperCala:

  1. Do NOT report security vulnerabilities in public GitHub issues or discussions.
  2. Please submit a report privately via GitHub Private Security Advisories.
  3. Alternatively, encrypt your advisory to @bootlace-dev using the release key published in the organization repository.

Response Timeline

  • Initial Assessment: Within 48 hours
  • Invariant Reproduction: Within 5 business days
  • Public Disclosure & Advisory: Coordinated following patch deployment

There aren't any published security advisories