Skip to content

Security: QuietFlare/horus-lineage-dev

SECURITY.md

Security Policy

Supported versions

Security fixes land on the latest release. Upgrade before reporting.

Reporting a vulnerability

Do not open a public issue for a security problem. Report it privately:

Include the impact you believe it has, the versions of horus-lineage and horus-runtime, and a minimal workflow that reproduces it.

What to expect

An acknowledgement within a week, then an agreed fix and disclosure timeline, and credit in the advisory if you want it.

Scope note

The plugin records paths, digests and the resolved command line, and never command output, file contents, or executor and target settings. See Sharing in the README. A record that carries more than that is a vulnerability, report it the same way.

Dependencies are audited with pip-audit and the tree is scanned with gitleaks on every push and pull request.

There aren't any published security advisories