Security fixes are applied to the latest released version of trustcheck.
If you believe an issue affects an older release, please report it anyway and include the affected version so impact can be evaluated.
Report suspected vulnerabilities through GitHub's private vulnerability reporting form:
Do not open a public issue for a vulnerability before coordinated disclosure. Use GitHub Issues only for non-sensitive bugs, documentation problems, and feature requests.
When reporting, include:
- a clear description of the issue
- reproduction steps or a proof of concept, if available
- the affected
trustcheckversion - any suggested mitigation or workaround
You can expect an initial acknowledgment within 7 business days.
After triage, the maintainer will aim to:
- confirm whether the report is reproducible
- assess severity and affected versions
- prepare a fix or mitigation when appropriate
- coordinate a responsible disclosure timeline