Skip to content

Security: hyperpolymath/nexia-list

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly.

Contact: j.d.a.jewell@open.ac.uk

Please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Assessment: Within 7 days
  • Fix/Mitigation: As soon as possible, depending on severity

Supported Versions

Only the latest version is supported with security updates.

Scope

This policy covers the nexia-list repository and its published artifacts:

  • Rust crates (nexia-core, nexia-desktop)
  • ReScript UI package
  • Tauri application binaries

Disclosure Policy

We follow coordinated disclosure. Please do not publicly disclose vulnerabilities until a fix has been released or 90 days have passed since the initial report.

There aren’t any published security advisories