USC releases receive security vulnerability updates according to the following schedule:
| Version | Supported |
|---|---|
| 0.2.x | ✅ |
| < 0.2.0 | ❌ |
The USC development team takes the security of our Zero-Trust Skill Compiler very seriously. If you discover a security vulnerability, please do NOT create a public issue.
Please report vulnerabilities via:
- GitHub Security Advisories: Submit a private advisory directly on the repository.
- Email: Send vulnerability details to
security@usc-project.internalor contact project maintainers.
Please include:
- A descriptive summary of the vulnerability
- Exact steps to reproduce or Proof of Concept (PoC)
- Potential impact and affected components (e.g., attestation verify, adapter sandbox, pipeline clean-room)
- Any proposed mitigations or fixes
We aim to respond to initial reports within 48 hours and provide a CVE/advisory with patch remediation.