Skip to content

Security: EtanHey/t3layer

SECURITY.md

Security Policy

Supported versions

T3Layer has not published a stable release. Security fixes are applied to the latest development branch only.

Reporting a vulnerability

Please do not open a public issue for a suspected vulnerability.

Use GitHub's private vulnerability reporting flow from the repository's Security tab and select Report a vulnerability. If private reporting is not available, contact the maintainer privately through the project owner's GitHub profile before sharing technical details.

Include:

  • the affected revision;
  • a minimal reproduction;
  • impact and attack preconditions;
  • whether credentials, local files, or external services are involved; and
  • any suggested mitigation.

Do not include live credentials, bearer tokens, WebSocket tickets, private transcripts, or personal data in the report.

You should receive an acknowledgment within seven days. Disclosure timing will be coordinated after the issue is reproduced and a remediation plan exists.

There aren't any published security advisories