Use GitHub private vulnerability reporting for vulnerability details. Do not open public issues for sensitive reports.
Include: affected version/commit, reproduction steps, impact, and any suggested fix.
Disclosure timelines are coordinated through the private report. No fixed response-time service level is offered. Critical issues affecting install integrity or evidence tampering are prioritized.
In scope: the curbpack CLI, embedded packs, GitHub Action, scripts/install.sh, and the release binaries. The npm wrapper is deferred and is not a supported installation channel.
Out of scope: customer product repos scanned by Curbpack; third-party packs you import; misuse of gate results as certification claims.
Curbpack prepares evidence for human review. A green check is not a
conformity assessment, CE mark, notified-body approval, or certification.