Only the latest major version of the KYA Manifest Standard is supported for security updates.
| Version | Supported |
|---|---|
| 0.1.x | ✅ Yes |
| < 0.1 | ❌ No |
For now you may open a public issue on GitHub. In the future, we may set up a private disclosure process.
If you discover a security flaw in the future or wish to do so privately for the KYA schema, linter, or protocol logic, please report it privately via:
- Email: security@cph.ai
- PGP Key:
-----BEGIN PGP PUBLIC KEY BLOCK-----
mDMEaXLTchYJKwYBBAHaRw8BAQdA1e243NTPfvN46VWC48tHjNMdx+Kqcb1Xbtta
4GqS4ZS0IUNQSC1BSSBTZWN1cml0eSA8c2VjdXJpdHlAY3BoLmFpPoiZBBMWCgBB
FiEEX/sM/XNyAq4vACSzRtkRt7ZG5dsFAmly03ICGwMFCQeEzgAFCwkIBwICIgIG
FQoJCAsCBBYCAwECHgcCF4AACgkQRtkRt7ZG5dt39AEA0ZhACGbACNr/DJinOYXw
GCdxT0l2tZfSfEGaSmZIIk4A/28Zfj1MMlUY5QvtXrpL207a3PyA3+IqsCiDqifK
Dy0NuDgEaXLTchIKKwYBBAGXVQEFAQEHQMnBBiH+gLG9XNqm0troeai1kHeZNGBf
gCavPDCBUexEAwEIB4h+BBgWCgAmFiEEX/sM/XNyAq4vACSzRtkRt7ZG5dsFAmly
03ICGwwFCQeEzgAACgkQRtkRt7ZG5dsHQAD/SzbFJO92oXpHRgzRTFTHI7TY0Bsb
OldhhZKB8iQJ8mcBAKgjSk53AlbC8h5ruTvbSFhAJkipoAB93W06Ygu+QPoB
=AkD3
-----END PGP PUBLIC KEY BLOCK-----
- PGP Fingerprint:
5FFB0CFD737202AE2F0024B346D911B7B646E5DB
Please include a detailed description of the vulnerability and a proof-of-concept if possible. We aim to acknowledge all reports within 48 hours.