Skip to content

Security: Soturine/echora

Security

SECURITY.md

Security Policy

Echora is currently pre-release research software.

Reporting

Please report security issues privately to the repository owner rather than opening a public issue when disclosure could expose users, credentials, private captures or a remotely exploitable vulnerability.

Until a dedicated security contact/process is published, use GitHub's private vulnerability reporting feature if enabled for this repository.

Scope

Security-sensitive areas include:

  • packet/capture/model parsers;
  • firmware provisioning and OTA;
  • API authentication/authorization;
  • raw/derived human-sensing data;
  • secrets and credentials;
  • dependency/supply-chain integrity.

Supported versions

No stable supported release exists yet. Security fixes target the current main branch until versioned releases begin.

Disclosure

Do not publish private capture data, credentials, exploit details or personal information in issue attachments.

There aren't any published security advisories