Skip to content

Security: s2-streamstore/komputer

Security

SECURITY.md

Security

Komputer is early software and should not yet be treated as a hardened multi-party isolation boundary.

Please report suspected vulnerabilities privately through GitHub's security advisory interface for s2-streamstore/komputer. Do not open a public issue until maintainers have had a reasonable opportunity to investigate.

Include:

  • the affected revision or release;
  • the admitted image profile and relevant configuration;
  • whether journal authority, adapter authority, sandboxing, credential isolation, or durable-format validation was bypassed;
  • a minimal reproducer or deterministic fault seed when possible; and
  • any evidence of externally visible duplicate, reordered, or unjournaled I/O.

Komputer's authenticated anchor and local-control protocols do not provide a general encrypted transport. Use a private network or encrypted tunnel where their documentation requires one.

There aren't any published security advisories