Skip to content

Security: cryspen/libcrux

SECURITY.md

Security Policy

Supported Versions

libcrux is still pre-release and does not support any specific versions yet.

Version Supported

Reporting a Vulnerability

Use the private Github vulnerability reporting or send an email to security-reports@cryspen.com

PRs or issues that do not follow the security policy will be closed.

Security Advisories

We believe that any bug in a cryptographic library is a potential security vulnerability. Starting February 2026, we will issue GitHub security advisories for any releases whose CHANGELOG includes bug-fixes, and encourage our users to upgrade.

Learn more about advisories related to cryspen/libcrux in the GitHub Advisory Database