Skip to content

Security: Crosseno/learning

Security

SECURITY.md

Security policy

Report vulnerabilities privately through the security contact configured for the Crosseno organization. Do not include sensitive production data in a public issue.

Treat manifests and pack metadata as untrusted input. Coverage masks must be rejected unless their stable-key digest, tokenization profile, ordinal-space ID, and ordinal count match the active answer pack. Clue text is deliberately absent from search contracts and must be escaped by its eventual renderer.

There aren't any published security advisories