This project is security-hardened but does not guarantee long-term support for all historical versions.
Security fixes, when issued, are applied to the latest release and main.
Report security issues privately.
- Email: contact@speedkit.eu
- Include:
- affected version / commit SHA
- reproduction steps / PoC (minimal)
- expected vs observed behavior
- impact assessment
Do not open public issues for active vulnerabilities.
mainis protected (PR-only, linear history, signed commits required).- Release tags are protected from update and deletion.
- CI execution is restricted to an allowlist of actions.
Look for the Verified badge on commits and merges.
git verify-commit <SHA>