Skip to content

Security: LucaDominici/forma

SECURITY.md

title Security Policy
doc_version 1.0.0
status active
last_review 2026-08-10
owner Luca Dominici
canonical_id security
tags
audience/dev
kind/security
related
PRIVACY.md

Security Policy

Supported versions

Forma is pre-1.0; only the latest 0.x release is supported.

Reporting a vulnerability

Please do not open a public issue for security problems.

Report privately via GitHub's private vulnerability reporting (Security → Report a vulnerability), or email luca.dominici.work@gmail.com.

We aim to acknowledge reports within 5 business days. Forma runs locally, has no runtime dependencies, and makes no network calls in its core commands — the expected surface is small, but reports are welcome.

There aren't any published security advisories