Skip to content

Security: cannatoshi/SimpleGo

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do NOT report security vulnerabilities through public GitHub issues.

Preferred Method: GitHub Private Vulnerability Reporting

  1. Go to the Security tab: https://github.com/cannatoshi/SimpleGo/security
  2. Click Report a vulnerability
  3. Fill out the form with details

What to Include

  • Type of vulnerability (e.g., buffer overflow, crypto weakness)
  • Affected component (e.g., smp_ratchet.c, smp_x448.c)
  • Step-by-step reproduction
  • Impact assessment
  • Your suggested fix (if any)

Response Timeline

Phase Timeframe
Initial acknowledgment Within 48 hours
Issue confirmation Within 5 business days
Fix development Based on severity
Public disclosure After fix is released

Severity Classification

Severity Description Response
CRITICAL Key compromise, RCE Immediate hotfix
HIGH Crypto weakness, auth bypass Priority fix
MEDIUM Limited impact Scheduled fix
LOW Minor issues Future update

Supported Versions

Version Supported
0.1.x (current) Yes
< 0.1.0 No

Safe Harbor

We consider security research conducted consistent with this policy to be authorized. We will not pursue legal action against researchers who act in good faith.


Security Hall of Fame

No vulnerabilities reported yet. Be the first!


This security policy was last updated on January 24, 2026.

There aren’t any published security advisories