| Version | Supported | Security SLA Target |
|---|---|---|
| 1.0.x | β | < 24h Critical CVEs |
| 0.1.x | β | Active Development |
The SYNTRA OS security engineering team takes all vulnerability disclosures with extreme seriousness. If you discover a security issue (e.g. memory corruption in sysfitd, privilege escalation via D-Bus, or sandbox escapes):
- DO NOT open a public GitHub issue.
- Email encrypted details to
security@syntra.io. - Include:
- Subsystem affected (
syntra-core/crates/*,libprism,syspatchd). - Proof-of-concept (PoC) code or reproduction steps.
- Assessment of CVSS severity score.
- Subsystem affected (
- Initial Response: Within 6 hours.
- Triage & Reproduction: Within 12 hours.
-
Patch Deployment (Critical / CVSS
$\ge 8.0$ ): Within < 24 hours via automated Kernel Livepatching or fast-track repository push. - Coordinated Public Disclosure: Minimum 14-day embargo window to allow downstream users to apply mitigations.
SYNTRA OS publishes real-time CSAF/VEX and CycloneDX SBOM feeds at https://security.syntra.io/vex/.