We currently provide security updates for the following versions:
| Version | Supported |
|---|---|
| 2.1.x | ✅ |
| 2.0.x | ❌ |
| < 2.0.0 | ❌ |
Do not open a public GitHub issue for security vulnerabilities.
If you believe you have found a security vulnerability in the Sibna Protocol, please report it via one of the following channels:
- Email: Send a detailed report to
security@sibna.example.com(replace with real address). - Encrypted Communication: Use the Sibna CLI tool to send an encrypted message to the security team's research identity (Identity:
SEC-RESEARCH-ID).
- A descriptive title.
- A technical description of the vulnerability.
- Steps to reproduce (Proof of Concept).
- Potential impact (e.g., remote code execution, key leakage).
- We will acknowledge receipt of your report within 48 hours.
- We will provide a timeline for the fix.
- We will coordinate a public disclosure date.
- We will credit the researcher (if desired) in the changelog.
Thank you for helping keep Sibna secure!