Skip to content

Security: jiangxt2/Yamazaki

SECURITY.md

Security Policy

Supported Versions

Yamazaki has no released or supported production versions. The project is an early-stage public project with a validated internal, controlled-network read-only POC and no supported production deployment.

Security reports about repository configuration, documentation, future design, or later implementations are still welcome.

Reporting a Vulnerability

Use GitHub's private vulnerability reporting to contact the maintainers securely.

Do not disclose vulnerability details, credentials, production data, internal endpoints, or exploit steps in a public Issue, Discussion, or pull request.

Include the following information when available:

  • A clear description of the issue and affected behavior.
  • Reproduction steps or a minimal proof of concept.
  • Potential impact and preconditions.
  • Relevant versions, configurations, logs, or evidence with secrets removed.
  • Suggested mitigations or fixes, if known.

Maintainers may request additional information through the private advisory. Public disclosure should occur only after a fix or mitigation is available and the disclosure timing has been coordinated.

There aren't any published security advisories