All Kormium projects are pre-1.0. Security fixes are released from main as a new patch or
minor version; older versions are not patched. Please upgrade to the latest release before
reporting.
Do not open a public issue for a security problem.
Report it through GitHub's private vulnerability reporting on the affected repository:
Security → Report a vulnerability. If that is unavailable, email
yaknyazsergei@gmail.com with [SECURITY] in the subject.
Please include:
- the affected repository and version,
- the target(s) involved (JVM / Native / Android / iOS / Node / Wasm),
- a description of the impact,
- a reproducer, if you have one.
- Acknowledgement within 7 days.
- An assessment — confirmed or not, with reasoning — within 30 days.
- A fix and release for confirmed issues, coordinated with you on timing.
- Credit in the release notes and advisory, unless you prefer to stay anonymous.
These are single-maintainer projects, so response times are best-effort rather than contractual. Thank you for reporting responsibly.