We take the security of Vane seriously. This document outlines how to report security vulnerabilities and our policy regarding security updates.
Only the latest stable release of Vane is supported with security updates. We recommend always running the latest version.
| Version | Supported |
|---|---|
| v1.1.4+ | β |
| < v1.1.4 | β |
Please do not report security vulnerabilities via public GitHub issues.
If you identify a security vulnerability in Vane, please report it privately through one of the following channels:
| Channel | Contact |
|---|---|
| π§ Email | alp@archey.com.tr |
| π¬ Discord | luppux (ID: 852103749228036136) |
| π GitHub | Security β Advisories β New private advisory |
- Include a detailed description of the vulnerability.
- Provide clear steps to reproduce the issue.
- Attach a Proof of Concept (PoC) if available.
- Specify the affected version(s) and operating system.
We will acknowledge your report within 48 hours, validate the vulnerability, and coordinate a release patch. We follow responsible disclosure principles and ask that you give us reasonable time to patch the issue before making it public.
- Report received β You receive an acknowledgment within 48 hours.
- Validation β We reproduce and verify the issue.
- Patch development β A fix is developed and tested.
- Release β A new version is published with the patch.
- Public disclosure β After the fix is distributed, the vulnerability may be publicly disclosed.
Vane uses cryptographic signatures to verify presets and binary integrity. The official public key is:
untrusted comment: minisign public key: 2A7CBD213C2CD2E8
RWTo0iw8Ib18KoSGwlXjG4Hlz+oMjaFhN6077H5nNlTH6KuJogHeUra1
You can verify download artifacts and remote preset payloads using this key with the minisign tool:
minisign -Vm <file> -P RWTo0iw8Ib18KoSGwlXjG4Hlz+oMjaFhN6077H5nNlTH6KuJogHeUra1