Operating policy

Security and disclosure

Package archives, dependencies and output are treated as untrusted. Preparation and execution run on a dedicated Linux host under a pinned gVisor policy. Runtime jobs have no network, production secrets, host sockets or writable package workspace. Resource limits are enforced outside the package process.

These controls and the qualification tests describe the tested boundary. They do not prove that packages are safe or that in-process observations cannot be forged. Read the methodology before interpreting a result.

Report a vulnerability

Use the repository’s private vulnerability reporting form. Include affected revisions, a minimal reproduction and the expected boundary. Do not publish credentials, private data or an active exploit in a public issue. If the form is unavailable, contact siddiksawani through the contact channel on that profile to arrange a private report.

Service incidents

The repository maintainer owns incident response. Public operational updates and resolved incident summaries are published through repository issues. Infrastructure failures are kept separate from package compatibility findings. Reports affected by a faulty runtime or policy are marked as historical evidence while the operator investigates.