Skip to content

Security: itsVentie/Latch

Security

SECURITY.md

Security Policy

Supported Versions

We officially support and patch only the latest minor release of pqc-proxy. Security fixes will not be backported to older legacy versions.

Reporting a Vulnerability

Do not open a public GitHub Issue for security-related bugs.

If you discover a security vulnerability (such as a memory leak, encryption bypass, or parser flaw), please report it responsibly by using one of the following methods:

  1. GitHub Private Vulnerability Reporting: Navigate to the "Security" tab of this repository, click on "Advisories", and select "Report a vulnerability".
  2. Direct Email: Send a detailed report to bugs@ventie.dev.

Please include the following information in your report:

  • A detailed description of the vulnerability and its potential impact.
  • Step-by-step instructions or a minimal proof-of-concept (PoC) to reproduce the issue.
  • Any potential mitigation steps you have identified.

Our Process

  • Acknowledgment: We will acknowledge receipt of your report within 48 hours.
  • Triage: We will investigate and validate the vulnerability within 7 days.
  • Resolution: If validated, we will coordinate a fix and release a patch version.
  • Disclosure: A public security advisory will be published alongside the patch release, crediting you for the discovery unless you prefer to remain anonymous.

There aren't any published security advisories