The purpose of this document is to outline how the Kani Project maintainers will handle any Security Vulnerabilities discovered.
We provide security patches for the latest release of Kani. This means that we will only address security vulnerabilities that affect the most recent release of this project.
Version | Supported |
---|---|
1.2.x |
✅ |
< 1.2.x |
❌ |
If you discover a security vulnerability in Kani, we encourage you to report it to us as soon as possible so that we can investigate and address the issue.
You can report a security vulnerability in Kani by:
- Creating a vulnerability report on our GitHub repository.
- Sending an email to [email protected].
When reporting a security vulnerability, please provide as much detail as possible about the issue, including how it can be reproduced and what the potential impact of the vulnerability may be.
We take the security of Kani very seriously. As such, we encourage responsible disclosure of security vulnerabilities in Kani. If you report a security vulnerability to us responsibly, we will credit you when we publish a Security Advisory.
We define responsible disclosure as follows:
- Disclosing the vulnerability directly to the Kani maintainers, without publicly disclosing it.
- Allowing us a reasonable amount of time to address the vulnerability before publicly disclosing it.
- Not exploiting the vulnerability or any related vulnerabilities to gain unauthorised access to systems or data.
By following this Security Policy, we aim to maintain the security of Kani and our users.
If you have any questions or concerns about this policy or Kani's security practices, please do
not hesitate to contact us at [email protected].