We take the security of the Siren SDK seriously. If you believe you have found a security vulnerability, please report it privately — do not open a public GitHub issue.
Report vulnerabilities through GitHub's private Security Advisories for this repository. This opens a private channel between you and the maintainers.
Please include as much detail as you can:
- A description of the vulnerability and its potential impact.
- Steps to reproduce, or a proof of concept.
- Any affected versions you are aware of.
We will acknowledge your report, investigate, and keep you informed of the resolution. Once a fix is released, we're happy to credit you unless you'd prefer to remain anonymous.
As this project is pre-1.0, security fixes are applied to the latest published release.