Security Policy
July 28, 2026 ยท View on GitHub
Reporting a Vulnerability
If you find a potential security vulnerability in composefs-rs, please report it by following these steps:
1. Use the GitHub Security Tab
This repository is set up to allow vulnerability reports through GitHub's Security Advisories feature. To report a vulnerability:
- Navigate to the repository's main page.
- Select the Security tab.
- Select Advisories from the left-hand sidebar.
- Click on Report a vulnerability.
- Fill in the required details and submit the report.
Following this process will create a private advisory for our maintainers to review.
2. Do Not Open Public Pull Requests, Issues, or Discussions
Please do not discuss the issue, create PRs, or start discussions about the vulnerability. This ensures the vulnerability is not widely exploited before a fix is provided.
Supported Versions
composefs-rs does not yet have stable release branches; security fixes
are made against the main branch.