Komputer is early software and should not yet be treated as a hardened multi-party isolation boundary.
Please report suspected vulnerabilities privately through GitHub's security
advisory interface for s2-streamstore/komputer. Do not open a public issue
until maintainers have had a reasonable opportunity to investigate.
Include:
- the affected revision or release;
- the admitted image profile and relevant configuration;
- whether journal authority, adapter authority, sandboxing, credential isolation, or durable-format validation was bypassed;
- a minimal reproducer or deterministic fault seed when possible; and
- any evidence of externally visible duplicate, reordered, or unjournaled I/O.
Komputer's authenticated anchor and local-control protocols do not provide a general encrypted transport. Use a private network or encrypted tunnel where their documentation requires one.