We currently support the following versions of BTXZ. We strongly recommend always running the latest version to ensure you have the most up-to-date security patches.
| Version | Supported |
|---|---|
| v1.2.x | ✅ |
| v1.1.x | ❌ |
| v1.0.x | ❌ |
| < v1.0 | ❌ |
We take the security of BTXZ seriously. If you have discovered a vulnerability, we appreciate your help in disclosing it to us in a responsible manner.
- Do not open a public GitHub issue. This allows us to patch the vulnerability before it can be exploited.
- Email us directly at BlackTechX@proton.me.
- If possible, please encrypt your message using our PGP key (Key ID:
0xXYZ...).
- If possible, please encrypt your message using our PGP key (Key ID:
- Include a detailed description of the vulnerability, steps to reproduce it, and any proof-of-concept code.
- We will acknowledge receipt of your report within 48 hours.
- We will investigate the issue and confirm its validity.
- We will provide an estimated timeline for a fix.
- We will credit you (if desired) in the release notes once the patch is published.
BTXZ relies on well-tested cryptographic primitives:
- AEAD: XChaCha20-Poly1305 (Go standard library
golang.org/x/crypto/chacha20poly1305) - KDF: Argon2id (Go standard library
golang.org/x/crypto/argon2) - Compression: LZMA2 (via
github.com/ulikunitz/xz)
We perform regular audits of our dependency tree to ensure no supply chain vulnerabilities are introduced.