POSEIDON is research software for discovering and certifying observations. It does not make authorization, enforcement, or response decisions. Consumers remain responsible for how an observation affects a security policy.
Please report suspected vulnerabilities privately to the repository owner rather than opening a public issue. Include the affected version, a minimal reproduction, expected impact, and whether signing keys or released artifacts may be affected.
- Never commit private signing keys. The repository ignores common key-file extensions.
- Use separate keys for development, package release, and online attestation.
- Treat a signing key compromise as a package-revocation event.
- A valid signature establishes provenance and integrity, not safety or production approval.
Until a stable release exists, security fixes are made on the latest main revision only.