Skip to content

Security: owgit/memento-native

Security

SECURITY.md

Security Policy

Supported versions

Security fixes are prioritized for:

  • Latest stable release
  • Previous patch line when feasible

Reporting a vulnerability

Please use GitHub Security Advisories (private reporting) when possible.

If private reporting is unavailable, open a minimal public issue without exploit details and request private follow-up.

Response targets (best effort)

  • Initial triage: within 3 business days
  • Severity assessment and mitigation plan: within 7 business days
  • Patch timing: depends on severity and reproducibility

Scope

In scope:

  • Capture/Timeline local processing pipeline
  • Update/install flow integrity
  • Data-at-rest handling in local storage
  • Permission and automation boundaries

Out of scope:

  • Local compromise where attacker already has root/admin access
  • Unsupported forked distributions not built from this repository

There aren’t any published security advisories