Skip to content

Security: Freecode100Year/usc

Security

.github/SECURITY.md

Security Policy

Supported Versions

USC releases receive security vulnerability updates according to the following schedule:

Version Supported
0.2.x ✅
< 0.2.0 ❌

Reporting a Vulnerability

The USC development team takes the security of our Zero-Trust Skill Compiler very seriously. If you discover a security vulnerability, please do NOT create a public issue.

Please report vulnerabilities via:

  1. GitHub Security Advisories: Submit a private advisory directly on the repository.
  2. Email: Send vulnerability details to security@usc-project.internal or contact project maintainers.

Please include:

  • A descriptive summary of the vulnerability
  • Exact steps to reproduce or Proof of Concept (PoC)
  • Potential impact and affected components (e.g., attestation verify, adapter sandbox, pipeline clean-room)
  • Any proposed mitigations or fixes

We aim to respond to initial reports within 48 hours and provide a CVE/advisory with patch remediation.

There aren't any published security advisories