Security reports should be made privately.
Please use GitHub's Private vulnerability reporting feature for the affected Kaiten repository when available.
Include, where possible:
- affected component and version or commit;
- description of the vulnerability;
- reproducible steps or proof of concept;
- expected security impact;
- known mitigations or workarounds.
Please do not open a public GitHub issue for an unpatched vulnerability.
KAITEN INC asks security researchers to provide a reasonable opportunity to investigate and address a vulnerability before public disclosure.
KAITEN INC will make reasonable efforts to acknowledge valid reports, assess their impact, coordinate remediation where appropriate, and publish relevant security information when a fix is available.
Unless a repository states otherwise, this policy covers Kaiten open-source projects maintained by KAITEN INC.
Third-party services, integrations, dependencies, and forks may have separate security reporting processes.