Last verified: 2026-05-02
Security fixes land on main first and ride the next tagged release (docs/VERSIONING.md). Older tags are best-effort unless explicitly declared as extended-support.
Please email the repository maintainer (GitHub profile contact) rather than filing a public issue for exploit-ready bugs.
Include:
fission-cli, loader, automation lane, etc.)Allow a reasonable coordination window before public disclosure.
Fission parses untrusted binaries locally. Not every crash or rejection counts as a security vulnerability:
If you are unsure, email first—we can triage quickly.
Do not attach malware, live offensive samples, or unsolicited exploit binaries to issues or pull requests. Do not paste credential-bearing or sensitive binaries publicly.
Preferred evidence:
benchmark/binary/) or publicly documented benign corporaOperational expectations for CI fixtures and escalation: docs/MALWARE_SAMPLE_POLICY.md.
Third-party vendored trees (THIRD_PARTY.md) inherit upstream policies; report critical issues upstream when they originate there.