Fission

Security policy

Last verified: 2026-05-02

Supported versions

Security fixes land on main first and ride the next tagged release (docs/VERSIONING.md). Older tags are best-effort unless explicitly declared as extended-support.

Reporting a vulnerability

Please email the repository maintainer (GitHub profile contact) rather than filing a public issue for exploit-ready bugs.

Include:

Allow a reasonable coordination window before public disclosure.

Crash, malformed binary, and parser bugs

Fission parses untrusted binaries locally. Not every crash or rejection counts as a security vulnerability:

If you are unsure, email first—we can triage quickly.

Samples and attachments

Do not attach malware, live offensive samples, or unsolicited exploit binaries to issues or pull requests. Do not paste credential-bearing or sensitive binaries publicly.

Preferred evidence:

Operational expectations for CI fixtures and escalation: docs/MALWARE_SAMPLE_POLICY.md.

Scope notes

Third-party vendored trees (THIRD_PARTY.md) inherit upstream policies; report critical issues upstream when they originate there.