Skip to content

Security: nisshi-io/nisshi

SECURITY.md

Security Policy

Supported Versions

Nisshi is pre-1.0 and moves quickly. Security fixes land on main and ship in the next release; we don't maintain older release branches.

Reporting a Vulnerability

Please don't open a public issue for a security vulnerability.

Preferred: use GitHub's private vulnerability reporting for this repository (Security tab → Report a vulnerability). This creates a private advisory visible only to maintainers until a fix is ready.

Fallback: email peter.james.morgan@gmail.com with details. Include:

  • The version or commit you tested against
  • Steps to reproduce, or a proof of concept
  • The impact you believe the issue has

We'll acknowledge your report, work with you to understand the impact, and coordinate on a disclosure timeline once a fix or mitigation is ready.

There aren't any published security advisories