Skip to content

Security: quantag/qbin

Security

SECURITY.md

Security Policy

Supported Versions

We release patches for security vulnerabilities under the following versions:

Version Supported
1.x ✅ Full support
0.x ❌ Not supported

Only the latest minor release of the 1.x series will receive security updates.


Reporting a Vulnerability

If you discover a security vulnerability in QBIN, please report it responsibly.

  • Do not create a public GitHub issue.
  • Instead, email the project security team at: security@quantag-it.com
  • Include a description of the vulnerability, steps to reproduce, and potential impact.

We will:

  1. Acknowledge receipt of your report within 72 hours.
  2. Provide a status update within 7 days.
  3. Work with you on a fix and coordinated disclosure timeline.

Scope

This policy covers:

  • QBIN specification reference implementations (compiler, decompiler, libraries)
  • Associated tooling in this repository

Out of scope:

  • Third-party integrations and forks
  • Issues unrelated to security (use GitHub Issues for those)

Preferred Languages

Please report vulnerabilities in English if possible.


Disclosure

We follow a responsible disclosure model. Once a fix is available and released, we will publicly disclose the vulnerability in the CHANGELOG and release notes.

There aren’t any published security advisories