Specht is an experimental project and does not yet provide a supported
security response SLA. The latest main branch is the only development
line receiving security fixes.
Do not open a public issue for an undisclosed vulnerability. Use GitHub's private vulnerability reporting or a private security advisory for this repository. If that option is unavailable, contact the maintainers through GitHub before disclosing the issue publicly.
Please include:
- Affected commit, release, or deployment configuration.
- Reproduction steps or a minimal proof of concept.
- Expected and observed behavior.
- Any known exploit prerequisites or impact.
Please allow reasonable time for assessment and remediation before public disclosure. Reports are handled on a best-effort basis while the project is in playtest.
Reports involving the Specht server, CLI, ingestion pipeline, parsers, authentication, authorization, deployment manifests, or CI workflows are in scope. Vulnerabilities in third-party tools or dependencies should be reported to their upstream maintainers as well, with relevant context included here.