Security: liesware/Vectis

SECURITY.md

Security Policy

Supported Versions

VersionSupported
0.8.xYes
Earlier versionsNo

Vectis 0.8.x is experimental. It has not completed an external security audit, and its API and signed-config contracts may change before 1.0.

Reporting a Vulnerability

Report suspected vulnerabilities privately to liesware@protonmail.com with the subject Vectis security report.

Include, where available:

  • affected Vectis version or commit;
  • impact and attack prerequisites;
  • minimal reproduction steps or proof of concept;
  • affected endpoint, configuration, storage backend, or artifact format; and
  • any proposed mitigation.

Do not open a public issue for an unpatched vulnerability. Do not send production secrets, plaintext records, API keys, unseal keys, private keys, or full sensitive audit data. If protected exchange is needed, request an appropriate channel in the initial report.

Security reports may be encrypted using the project's OpenPGP public key. Verify its fingerprint before use:

B24F 5892 7262 09ED 7C7F 6A8A 367C 0B31 BA81 6201 AB79 A095 B6

We aim to acknowledge reports within five business days and provide status updates while investigating. This is not a guaranteed remediation SLA and Vectis does not currently offer a bug bounty program.

Scope

Security reports are welcome for:

  • Vectis source code and official release artifacts;
  • cryptographic primitives and protocol implementations;
  • signed configuration, key material handling, storage, lifecycle, and authorization behavior;
  • HTTP and CLI inputs, local artifact parsers, audit verification, and release supply-chain controls.

Reports about unsupported local modifications, hypothetical issues without a plausible impact path, or availability problems requiring resources outside the documented limits may receive lower priority. Good-faith reports with a clear security impact are still welcome.

Release Verification

Official releases publish platform archives, SHA256SUMS, and SHA256SUMS.sigstore.json. Download the archives and both verification files, then verify the checksum manifest against the exact release tag:

cosign verify-blob \
--bundle SHA256SUMS.sigstore.json \
--certificate-identity \
"https://github.com/liesware/Vectis/.github/workflows/release.yml@refs/tags/vX.Y.Z" \
--certificate-oidc-issuer \
"https://token.actions.githubusercontent.com" \
SHA256SUMS \
&& sha256sum --ignore-missing -c SHA256SUMS

Replace vX.Y.Z with the downloaded release tag. The && makes the checksum check run only after the signature verifies, so a tampered manifest cannot pass by having the checksum step run regardless. --ignore-missing verifies only the archives you actually downloaded, since SHA256SUMS lists every platform. The Cosign bundle authenticates the checksum manifest using the release workflow's GitHub OIDC identity. The checksum verification then binds every downloaded archive to that signed manifest. GitHub artifact attestations separately provide build provenance for each release archive.

Disclosure

Please allow time to investigate and prepare a fix before public disclosure. When a report is resolved, Vectis will coordinate disclosure with the reporter where practical. Reporter credit is given only with explicit permission.

Security fixes and advisories are recorded in release notes and CHANGELOG.md. Consult README.md and doc/ThreatModel.md for current security boundaries and known limitations.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Security: liesware/Vectis

SECURITY.md

Security Policy

Supported Versions

VersionSupported
0.8.xYes
Earlier versionsNo

Vectis 0.8.x is experimental. It has not completed an external security audit, and its API and signed-config contracts may change before 1.0.

Reporting a Vulnerability

Report suspected vulnerabilities privately to liesware@protonmail.com with the subject Vectis security report.

Include, where available:

  • affected Vectis version or commit;
  • impact and attack prerequisites;
  • minimal reproduction steps or proof of concept;
  • affected endpoint, configuration, storage backend, or artifact format; and
  • any proposed mitigation.

Do not open a public issue for an unpatched vulnerability. Do not send production secrets, plaintext records, API keys, unseal keys, private keys, or full sensitive audit data. If protected exchange is needed, request an appropriate channel in the initial report.

Security reports may be encrypted using the project's OpenPGP public key. Verify its fingerprint before use:

B24F 5892 7262 09ED 7C7F 6A8A 367C 0B31 BA81 6201 AB79 A095 B6

We aim to acknowledge reports within five business days and provide status updates while investigating. This is not a guaranteed remediation SLA and Vectis does not currently offer a bug bounty program.

Scope

Security reports are welcome for:

  • Vectis source code and official release artifacts;
  • cryptographic primitives and protocol implementations;
  • signed configuration, key material handling, storage, lifecycle, and authorization behavior;
  • HTTP and CLI inputs, local artifact parsers, audit verification, and release supply-chain controls.

Reports about unsupported local modifications, hypothetical issues without a plausible impact path, or availability problems requiring resources outside the documented limits may receive lower priority. Good-faith reports with a clear security impact are still welcome.

Release Verification

Official releases publish platform archives, SHA256SUMS, and SHA256SUMS.sigstore.json. Download the archives and both verification files, then verify the checksum manifest against the exact release tag:

cosign verify-blob \
--bundle SHA256SUMS.sigstore.json \
--certificate-identity \
"https://github.com/liesware/Vectis/.github/workflows/release.yml@refs/tags/vX.Y.Z" \
--certificate-oidc-issuer \
"https://token.actions.githubusercontent.com" \
SHA256SUMS \
&& sha256sum --ignore-missing -c SHA256SUMS

Replace vX.Y.Z with the downloaded release tag. The && makes the checksum check run only after the signature verifies, so a tampered manifest cannot pass by having the checksum step run regardless. --ignore-missing verifies only the archives you actually downloaded, since SHA256SUMS lists every platform. The Cosign bundle authenticates the checksum manifest using the release workflow's GitHub OIDC identity. The checksum verification then binds every downloaded archive to that signed manifest. GitHub artifact attestations separately provide build provenance for each release archive.

Disclosure

Please allow time to investigate and prepare a fix before public disclosure. When a report is resolved, Vectis will coordinate disclosure with the reporter where practical. Reporter credit is given only with explicit permission.

Security fixes and advisories are recorded in release notes and CHANGELOG.md. Consult README.md and doc/ThreatModel.md for current security boundaries and known limitations.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: liesware/Vectis

SECURITY.md

Security Policy

Supported Versions

VersionSupported
0.8.xYes
Earlier versionsNo

Vectis 0.8.x is experimental. It has not completed an external security audit, and its API and signed-config contracts may change before 1.0.

Reporting a Vulnerability

Report suspected vulnerabilities privately to liesware@protonmail.com with the subject Vectis security report.

Include, where available:

  • affected Vectis version or commit;
  • impact and attack prerequisites;
  • minimal reproduction steps or proof of concept;
  • affected endpoint, configuration, storage backend, or artifact format; and
  • any proposed mitigation.

Do not open a public issue for an unpatched vulnerability. Do not send production secrets, plaintext records, API keys, unseal keys, private keys, or full sensitive audit data. If protected exchange is needed, request an appropriate channel in the initial report.

Security reports may be encrypted using the project's OpenPGP public key. Verify its fingerprint before use:

B24F 5892 7262 09ED 7C7F 6A8A 367C 0B31 BA81 6201 AB79 A095 B6

We aim to acknowledge reports within five business days and provide status updates while investigating. This is not a guaranteed remediation SLA and Vectis does not currently offer a bug bounty program.

Scope

Security reports are welcome for:

  • Vectis source code and official release artifacts;
  • cryptographic primitives and protocol implementations;
  • signed configuration, key material handling, storage, lifecycle, and authorization behavior;
  • HTTP and CLI inputs, local artifact parsers, audit verification, and release supply-chain controls.

Reports about unsupported local modifications, hypothetical issues without a plausible impact path, or availability problems requiring resources outside the documented limits may receive lower priority. Good-faith reports with a clear security impact are still welcome.

Release Verification

Official releases publish platform archives, SHA256SUMS, and SHA256SUMS.sigstore.json. Download the archives and both verification files, then verify the checksum manifest against the exact release tag:

cosign verify-blob \
--bundle SHA256SUMS.sigstore.json \
--certificate-identity \
"https://github.com/liesware/Vectis/.github/workflows/release.yml@refs/tags/vX.Y.Z" \
--certificate-oidc-issuer \
"https://token.actions.githubusercontent.com" \
SHA256SUMS \
&& sha256sum --ignore-missing -c SHA256SUMS

Replace vX.Y.Z with the downloaded release tag. The && makes the checksum check run only after the signature verifies, so a tampered manifest cannot pass by having the checksum step run regardless. --ignore-missing verifies only the archives you actually downloaded, since SHA256SUMS lists every platform. The Cosign bundle authenticates the checksum manifest using the release workflow's GitHub OIDC identity. The checksum verification then binds every downloaded archive to that signed manifest. GitHub artifact attestations separately provide build provenance for each release archive.

Disclosure

Please allow time to investigate and prepare a fix before public disclosure. When a report is resolved, Vectis will coordinate disclosure with the reporter where practical. Reporter credit is given only with explicit permission.

Security fixes and advisories are recorded in release notes and CHANGELOG.md. Consult README.md and doc/ThreatModel.md for current security boundaries and known limitations.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: liesware/Vectis

SECURITY.md

Security Policy

Supported Versions

VersionSupported
0.8.xYes
Earlier versionsNo

Vectis 0.8.x is experimental. It has not completed an external security audit, and its API and signed-config contracts may change before 1.0.

Reporting a Vulnerability

Report suspected vulnerabilities privately to liesware@protonmail.com with the subject Vectis security report.

Include, where available:

  • affected Vectis version or commit;
  • impact and attack prerequisites;
  • minimal reproduction steps or proof of concept;
  • affected endpoint, configuration, storage backend, or artifact format; and
  • any proposed mitigation.

Do not open a public issue for an unpatched vulnerability. Do not send production secrets, plaintext records, API keys, unseal keys, private keys, or full sensitive audit data. If protected exchange is needed, request an appropriate channel in the initial report.

Security reports may be encrypted using the project's OpenPGP public key. Verify its fingerprint before use:

B24F 5892 7262 09ED 7C7F 6A8A 367C 0B31 BA81 6201 AB79 A095 B6

We aim to acknowledge reports within five business days and provide status updates while investigating. This is not a guaranteed remediation SLA and Vectis does not currently offer a bug bounty program.

Scope

Security reports are welcome for:

  • Vectis source code and official release artifacts;
  • cryptographic primitives and protocol implementations;
  • signed configuration, key material handling, storage, lifecycle, and authorization behavior;
  • HTTP and CLI inputs, local artifact parsers, audit verification, and release supply-chain controls.

Reports about unsupported local modifications, hypothetical issues without a plausible impact path, or availability problems requiring resources outside the documented limits may receive lower priority. Good-faith reports with a clear security impact are still welcome.

Release Verification

Official releases publish platform archives, SHA256SUMS, and SHA256SUMS.sigstore.json. Download the archives and both verification files, then verify the checksum manifest against the exact release tag:

cosign verify-blob \
--bundle SHA256SUMS.sigstore.json \
--certificate-identity \
"https://github.com/liesware/Vectis/.github/workflows/release.yml@refs/tags/vX.Y.Z" \
--certificate-oidc-issuer \
"https://token.actions.githubusercontent.com" \
SHA256SUMS \
&& sha256sum --ignore-missing -c SHA256SUMS

Replace vX.Y.Z with the downloaded release tag. The && makes the checksum check run only after the signature verifies, so a tampered manifest cannot pass by having the checksum step run regardless. --ignore-missing verifies only the archives you actually downloaded, since SHA256SUMS lists every platform. The Cosign bundle authenticates the checksum manifest using the release workflow's GitHub OIDC identity. The checksum verification then binds every downloaded archive to that signed manifest. GitHub artifact attestations separately provide build provenance for each release archive.

Disclosure

Please allow time to investigate and prepare a fix before public disclosure. When a report is resolved, Vectis will coordinate disclosure with the reporter where practical. Reporter credit is given only with explicit permission.

Security fixes and advisories are recorded in release notes and CHANGELOG.md. Consult README.md and doc/ThreatModel.md for current security boundaries and known limitations.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Security: liesware/Vectis

SECURITY.md

Security Policy

Supported Versions

VersionSupported
0.8.xYes
Earlier versionsNo

Vectis 0.8.x is experimental. It has not completed an external security audit, and its API and signed-config contracts may change before 1.0.

Reporting a Vulnerability

Report suspected vulnerabilities privately to liesware@protonmail.com with the subject Vectis security report.

Include, where available:

  • affected Vectis version or commit;
  • impact and attack prerequisites;
  • minimal reproduction steps or proof of concept;
  • affected endpoint, configuration, storage backend, or artifact format; and
  • any proposed mitigation.

Do not open a public issue for an unpatched vulnerability. Do not send production secrets, plaintext records, API keys, unseal keys, private keys, or full sensitive audit data. If protected exchange is needed, request an appropriate channel in the initial report.

Security reports may be encrypted using the project's OpenPGP public key. Verify its fingerprint before use:

B24F 5892 7262 09ED 7C7F 6A8A 367C 0B31 BA81 6201 AB79 A095 B6

We aim to acknowledge reports within five business days and provide status updates while investigating. This is not a guaranteed remediation SLA and Vectis does not currently offer a bug bounty program.

Scope

Security reports are welcome for:

  • Vectis source code and official release artifacts;
  • cryptographic primitives and protocol implementations;
  • signed configuration, key material handling, storage, lifecycle, and authorization behavior;
  • HTTP and CLI inputs, local artifact parsers, audit verification, and release supply-chain controls.

Reports about unsupported local modifications, hypothetical issues without a plausible impact path, or availability problems requiring resources outside the documented limits may receive lower priority. Good-faith reports with a clear security impact are still welcome.

Release Verification

Official releases publish platform archives, SHA256SUMS, and SHA256SUMS.sigstore.json. Download the archives and both verification files, then verify the checksum manifest against the exact release tag:

cosign verify-blob \
--bundle SHA256SUMS.sigstore.json \
--certificate-identity \
"https://github.com/liesware/Vectis/.github/workflows/release.yml@refs/tags/vX.Y.Z" \
--certificate-oidc-issuer \
"https://token.actions.githubusercontent.com" \
SHA256SUMS \
&& sha256sum --ignore-missing -c SHA256SUMS

Replace vX.Y.Z with the downloaded release tag. The && makes the checksum check run only after the signature verifies, so a tampered manifest cannot pass by having the checksum step run regardless. --ignore-missing verifies only the archives you actually downloaded, since SHA256SUMS lists every platform. The Cosign bundle authenticates the checksum manifest using the release workflow's GitHub OIDC identity. The checksum verification then binds every downloaded archive to that signed manifest. GitHub artifact attestations separately provide build provenance for each release archive.

Disclosure

Please allow time to investigate and prepare a fix before public disclosure. When a report is resolved, Vectis will coordinate disclosure with the reporter where practical. Reporter credit is given only with explicit permission.

Security fixes and advisories are recorded in release notes and CHANGELOG.md. Consult README.md and doc/ThreatModel.md for current security boundaries and known limitations.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: liesware/Vectis

SECURITY.md

Security Policy

Supported Versions

VersionSupported
0.8.xYes
Earlier versionsNo

Vectis 0.8.x is experimental. It has not completed an external security audit, and its API and signed-config contracts may change before 1.0.

Reporting a Vulnerability

Report suspected vulnerabilities privately to liesware@protonmail.com with the subject Vectis security report.

Include, where available:

  • affected Vectis version or commit;
  • impact and attack prerequisites;
  • minimal reproduction steps or proof of concept;
  • affected endpoint, configuration, storage backend, or artifact format; and
  • any proposed mitigation.

Do not open a public issue for an unpatched vulnerability. Do not send production secrets, plaintext records, API keys, unseal keys, private keys, or full sensitive audit data. If protected exchange is needed, request an appropriate channel in the initial report.

Security reports may be encrypted using the project's OpenPGP public key. Verify its fingerprint before use:

B24F 5892 7262 09ED 7C7F 6A8A 367C 0B31 BA81 6201 AB79 A095 B6

We aim to acknowledge reports within five business days and provide status updates while investigating. This is not a guaranteed remediation SLA and Vectis does not currently offer a bug bounty program.

Scope

Security reports are welcome for:

  • Vectis source code and official release artifacts;
  • cryptographic primitives and protocol implementations;
  • signed configuration, key material handling, storage, lifecycle, and authorization behavior;
  • HTTP and CLI inputs, local artifact parsers, audit verification, and release supply-chain controls.

Reports about unsupported local modifications, hypothetical issues without a plausible impact path, or availability problems requiring resources outside the documented limits may receive lower priority. Good-faith reports with a clear security impact are still welcome.

Release Verification

Official releases publish platform archives, SHA256SUMS, and SHA256SUMS.sigstore.json. Download the archives and both verification files, then verify the checksum manifest against the exact release tag:

cosign verify-blob \
--bundle SHA256SUMS.sigstore.json \
--certificate-identity \
"https://github.com/liesware/Vectis/.github/workflows/release.yml@refs/tags/vX.Y.Z" \
--certificate-oidc-issuer \
"https://token.actions.githubusercontent.com" \
SHA256SUMS \
&& sha256sum --ignore-missing -c SHA256SUMS

Replace vX.Y.Z with the downloaded release tag. The && makes the checksum check run only after the signature verifies, so a tampered manifest cannot pass by having the checksum step run regardless. --ignore-missing verifies only the archives you actually downloaded, since SHA256SUMS lists every platform. The Cosign bundle authenticates the checksum manifest using the release workflow's GitHub OIDC identity. The checksum verification then binds every downloaded archive to that signed manifest. GitHub artifact attestations separately provide build provenance for each release archive.

Disclosure

Please allow time to investigate and prepare a fix before public disclosure. When a report is resolved, Vectis will coordinate disclosure with the reporter where practical. Reporter credit is given only with explicit permission.

Security fixes and advisories are recorded in release notes and CHANGELOG.md. Consult README.md and doc/ThreatModel.md for current security boundaries and known limitations.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: liesware/Vectis

SECURITY.md

Security Policy

Supported Versions

VersionSupported
0.8.xYes
Earlier versionsNo

Vectis 0.8.x is experimental. It has not completed an external security audit, and its API and signed-config contracts may change before 1.0.

Reporting a Vulnerability

Report suspected vulnerabilities privately to liesware@protonmail.com with the subject Vectis security report.

Include, where available:

  • affected Vectis version or commit;
  • impact and attack prerequisites;
  • minimal reproduction steps or proof of concept;
  • affected endpoint, configuration, storage backend, or artifact format; and
  • any proposed mitigation.

Do not open a public issue for an unpatched vulnerability. Do not send production secrets, plaintext records, API keys, unseal keys, private keys, or full sensitive audit data. If protected exchange is needed, request an appropriate channel in the initial report.

Security reports may be encrypted using the project's OpenPGP public key. Verify its fingerprint before use:

B24F 5892 7262 09ED 7C7F 6A8A 367C 0B31 BA81 6201 AB79 A095 B6

We aim to acknowledge reports within five business days and provide status updates while investigating. This is not a guaranteed remediation SLA and Vectis does not currently offer a bug bounty program.

Scope

Security reports are welcome for:

  • Vectis source code and official release artifacts;
  • cryptographic primitives and protocol implementations;
  • signed configuration, key material handling, storage, lifecycle, and authorization behavior;
  • HTTP and CLI inputs, local artifact parsers, audit verification, and release supply-chain controls.

Reports about unsupported local modifications, hypothetical issues without a plausible impact path, or availability problems requiring resources outside the documented limits may receive lower priority. Good-faith reports with a clear security impact are still welcome.

Release Verification

Official releases publish platform archives, SHA256SUMS, and SHA256SUMS.sigstore.json. Download the archives and both verification files, then verify the checksum manifest against the exact release tag:

cosign verify-blob \
--bundle SHA256SUMS.sigstore.json \
--certificate-identity \
"https://github.com/liesware/Vectis/.github/workflows/release.yml@refs/tags/vX.Y.Z" \
--certificate-oidc-issuer \
"https://token.actions.githubusercontent.com" \
SHA256SUMS \
&& sha256sum --ignore-missing -c SHA256SUMS

Replace vX.Y.Z with the downloaded release tag. The && makes the checksum check run only after the signature verifies, so a tampered manifest cannot pass by having the checksum step run regardless. --ignore-missing verifies only the archives you actually downloaded, since SHA256SUMS lists every platform. The Cosign bundle authenticates the checksum manifest using the release workflow's GitHub OIDC identity. The checksum verification then binds every downloaded archive to that signed manifest. GitHub artifact attestations separately provide build provenance for each release archive.

Disclosure

Please allow time to investigate and prepare a fix before public disclosure. When a report is resolved, Vectis will coordinate disclosure with the reporter where practical. Reporter credit is given only with explicit permission.

Security fixes and advisories are recorded in release notes and CHANGELOG.md. Consult README.md and doc/ThreatModel.md for current security boundaries and known limitations.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Security: liesware/Vectis

SECURITY.md

Security Policy

Supported Versions

VersionSupported
0.8.xYes
Earlier versionsNo

Vectis 0.8.x is experimental. It has not completed an external security audit, and its API and signed-config contracts may change before 1.0.

Reporting a Vulnerability

Report suspected vulnerabilities privately to liesware@protonmail.com with the subject Vectis security report.

Include, where available:

  • affected Vectis version or commit;
  • impact and attack prerequisites;
  • minimal reproduction steps or proof of concept;
  • affected endpoint, configuration, storage backend, or artifact format; and
  • any proposed mitigation.

Do not open a public issue for an unpatched vulnerability. Do not send production secrets, plaintext records, API keys, unseal keys, private keys, or full sensitive audit data. If protected exchange is needed, request an appropriate channel in the initial report.

Security reports may be encrypted using the project's OpenPGP public key. Verify its fingerprint before use:

B24F 5892 7262 09ED 7C7F 6A8A 367C 0B31 BA81 6201 AB79 A095 B6

We aim to acknowledge reports within five business days and provide status updates while investigating. This is not a guaranteed remediation SLA and Vectis does not currently offer a bug bounty program.

Scope

Security reports are welcome for:

  • Vectis source code and official release artifacts;
  • cryptographic primitives and protocol implementations;
  • signed configuration, key material handling, storage, lifecycle, and authorization behavior;
  • HTTP and CLI inputs, local artifact parsers, audit verification, and release supply-chain controls.

Reports about unsupported local modifications, hypothetical issues without a plausible impact path, or availability problems requiring resources outside the documented limits may receive lower priority. Good-faith reports with a clear security impact are still welcome.

Release Verification

Official releases publish platform archives, SHA256SUMS, and SHA256SUMS.sigstore.json. Download the archives and both verification files, then verify the checksum manifest against the exact release tag:

cosign verify-blob \
--bundle SHA256SUMS.sigstore.json \
--certificate-identity \
"https://github.com/liesware/Vectis/.github/workflows/release.yml@refs/tags/vX.Y.Z" \
--certificate-oidc-issuer \
"https://token.actions.githubusercontent.com" \
SHA256SUMS \
&& sha256sum --ignore-missing -c SHA256SUMS

Replace vX.Y.Z with the downloaded release tag. The && makes the checksum check run only after the signature verifies, so a tampered manifest cannot pass by having the checksum step run regardless. --ignore-missing verifies only the archives you actually downloaded, since SHA256SUMS lists every platform. The Cosign bundle authenticates the checksum manifest using the release workflow's GitHub OIDC identity. The checksum verification then binds every downloaded archive to that signed manifest. GitHub artifact attestations separately provide build provenance for each release archive.

Disclosure

Please allow time to investigate and prepare a fix before public disclosure. When a report is resolved, Vectis will coordinate disclosure with the reporter where practical. Reporter credit is given only with explicit permission.

Security fixes and advisories are recorded in release notes and CHANGELOG.md. Consult README.md and doc/ThreatModel.md for current security boundaries and known limitations.

There aren't any published security advisories