Skip to content

Security: RI-SE/curbpack

SECURITY.md

Security

Reporting

Use GitHub private vulnerability reporting for vulnerability details. Do not open public issues for sensitive reports.

Include: affected version/commit, reproduction steps, impact, and any suggested fix.

Response

Disclosure timelines are coordinated through the private report. No fixed response-time service level is offered. Critical issues affecting install integrity or evidence tampering are prioritized.

Scope

In scope: the curbpack CLI, embedded packs, GitHub Action, scripts/install.sh, and the release binaries. The npm wrapper is deferred and is not a supported installation channel.

Out of scope: customer product repos scanned by Curbpack; third-party packs you import; misuse of gate results as certification claims.

Claim safety

Curbpack prepares evidence for human review. A green check is not a conformity assessment, CE mark, notified-body approval, or certification.

There aren't any published security advisories