Echora is currently pre-release research software.
Please report security issues privately to the repository owner rather than opening a public issue when disclosure could expose users, credentials, private captures or a remotely exploitable vulnerability.
Until a dedicated security contact/process is published, use GitHub's private vulnerability reporting feature if enabled for this repository.
Security-sensitive areas include:
- packet/capture/model parsers;
- firmware provisioning and OTA;
- API authentication/authorization;
- raw/derived human-sensing data;
- secrets and credentials;
- dependency/supply-chain integrity.
No stable supported release exists yet. Security fixes target the current main branch until versioned releases begin.
Do not publish private capture data, credentials, exploit details or personal information in issue attachments.