Report suspected vulnerabilities by emailing vraman2811@gmail.com. Include the affected crate name, crate version, reproduction steps, and an impact assessment.
The project will make a best-effort acknowledgement within a few business days. There is no formal SLA and no bug bounty currently.
Security fixes target the latest 0.1.0-alpha.x line. Older alpha releases are not patched.
Coordinated disclosure is preferred. The default disclosure window is 90 days unless a different timeline is agreed during triage.
Examples include memory safety issues, data leakage between processes through shared memory, denial of service through crafted frames, or bugs that let one process corrupt another process's data.