Skip to content

Security: Digvijay/Rapp

Security

SECURITY.md

Security Policy

Rapp provides schema-safe binary caching. This document describes how to report a vulnerability and what response to expect.

Reporting a vulnerability

Do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Report vulnerabilities privately through either of the following channels:

Please include as much of the following as you can provide:

  • The type of issue and the affected component or package
  • Full paths of the source files related to the issue
  • The affected version, commit, or package version
  • Step-by-step instructions to reproduce
  • Proof-of-concept or exploit code, if available
  • The impact of the issue, including how an attacker might exploit it

If this project is transferred to Microsoft

This repository is prepared for review by the Microsoft Open Source Programs Office. If ownership transfers to Microsoft, security reporting moves to the Microsoft Security Response Center (MSRC) and this policy will be replaced by the standard MSRC policy:

Until such a transfer occurs, use the maintainer channels above. Do not send reports for this project to MSRC, because MSRC does not currently own this code.

Response targets

Stage Target
Acknowledgement of report 3 business days
Initial assessment and severity triage 10 business days
Fix or documented mitigation for High/Critical 90 days from triage

These are best-effort targets for an independently maintained project, not a contractual service-level agreement. See SUPPORT.md for the support model.

Supported versions

Security fixes are applied to the latest released minor version. Older versions are not patched. See SUPPORT.md for the full support and lifecycle statement.

Disclosure policy

This project follows coordinated disclosure. Issues are disclosed publicly through a GitHub Security Advisory once a fix or documented mitigation is available. Reporters are credited unless they ask not to be.

Security considerations for users

Rapp deserializes binary payloads from cache stores. Treat the cache as a trust boundary: protect the transport and the store, and do not rely on schema hashing as an authentication or integrity mechanism against an attacker who can write to the cache.

Build-time code generation is part of this project's design. Source generators execute inside the compiler process during build. Only build code you trust, and review generated output when it participates in a security decision.

There aren't any published security advisories