Security

Responsible disclosure

Confium takes security reports seriously. This page describes what's in scope, how to report, and the response you can expect.


How to report

Email security@confium.org with:

  1. A description of the issue and its impact.
  2. Steps to reproduce (code, commands, or test case).
  3. Affected versions, if known.
  4. Any suggested mitigations.

For sensitive material, encrypt to the project PGP key (keys.openpgp.org).

In scope

TargetIn scope?
Confium engine source (confium/confium) Yes
Ruby bindings (confium/confium-ruby) Yes
WASM verifier (confium/confium/crates/confium-wasm) Yes
Public website (confium/confium.github.io) Yes
Published packages on crates.io, RubyGems, npm Yes
Third-party plugins (report to the plugin author) No
Issues in your application code that consumes Confium No
Vulnerabilities in dependencies (report upstream) No

Response timeline

What we ask of reporters

Bounty

Confium does not run a paid bounty program at this time. Significant contributions to security will be acknowledged publicly (with the reporter's consent) in the release notes.

Past advisories

Published advisories appear on GitHub Security Advisories.