42 lines
1.8 KiB
Markdown
42 lines
1.8 KiB
Markdown
# Security Policy
|
|
|
|
## Supported code
|
|
|
|
Security fixes target the current `main` branch. Historical research and
|
|
experiment branches are evidence, not supported release channels.
|
|
|
|
## Reporting a vulnerability
|
|
|
|
Report suspected vulnerabilities privately to
|
|
[`security@itworx.tech`](mailto:security@itworx.tech). Do not
|
|
publish exploit chains, console-specific privileged addresses, credentials,
|
|
private network details, signing material, proprietary SDK or firmware
|
|
material, copyrighted dumps, payload delivery details that expose a live
|
|
target, or unredacted crash dumps in a public issue.
|
|
|
|
Include the affected component and commit, firmware or adapter boundary, a
|
|
minimal reproduction using synthetic inputs where possible, expected and
|
|
observed behaviour, and likely impact. Note whether the issue affects input
|
|
validation, ownership, lifecycle cleanup, firmware gating, artifact
|
|
provenance, hashing, resource bounds, or a documented safety boundary.
|
|
|
|
## Supported security boundary
|
|
|
|
Chimera GFX treats platform adapters, firmware assumptions, and native memory
|
|
boundaries as untrusted until explicitly validated. Contributions must preserve
|
|
bounded parsing, fail-closed compatibility checks, write-free diagnostics by
|
|
default, and the release requirements in `SAFETY.md`, `AGENTS.md`,
|
|
`FIRMWARE_COMPATIBILITY.md`, and the accepted ADRs. They must not silently add
|
|
deployment, automatic startup, proprietary dependencies, kernel or hypervisor
|
|
functionality, DRM bypasses, unbounded hardware access, or unsupported
|
|
compatibility claims.
|
|
|
|
Generated ELF files, core dumps, local build trees, device captures,
|
|
credentials, and operator-specific infrastructure are not source artifacts and
|
|
must not be committed.
|
|
|
|
## Disclosure
|
|
|
|
Coordinate remediation and disclosure with the repository owner before
|
|
publishing details that would materially increase exploitation risk.
|