Skip to content

Security: LoganVoss/POSEIDON

Security

SECURITY.md

Security policy

POSEIDON is research software for discovering and certifying observations. It does not make authorization, enforcement, or response decisions. Consumers remain responsible for how an observation affects a security policy.

Please report suspected vulnerabilities privately to the repository owner rather than opening a public issue. Include the affected version, a minimal reproduction, expected impact, and whether signing keys or released artifacts may be affected.

Key handling

  • Never commit private signing keys. The repository ignores common key-file extensions.
  • Use separate keys for development, package release, and online attestation.
  • Treat a signing key compromise as a package-revocation event.
  • A valid signature establishes provenance and integrity, not safety or production approval.

Supported line

Until a stable release exists, security fixes are made on the latest main revision only.

There aren't any published security advisories