Security fixes are currently targeted at:
- the latest
mainbranch - the most recent tagged release
Older pre-release snapshots and unpublished local branches should be treated as unsupported.
Please do not open a public GitHub issue for suspected vulnerabilities.
Instead:
- Email
muthmann@physik.uni-bielefeld.dewith the subject lineAugurRS security report. - Include the affected version or commit, platform details, impact, and clear reproduction steps.
- Attach logs, traces, or proof-of-concept material only when needed to explain the issue.
- If private GitHub Security Advisories are enabled for the repository, you may use that channel instead of email.
- An initial acknowledgement target is within 5 business days.
- A follow-up status update target is within 10 business days after acknowledgement.
- Coordinated disclosure is preferred once a fix or mitigation is available.
Please report vulnerabilities in:
- USB transport or protocol handling
- recording, parsing, or configuration loading behavior
- release artifacts or packaging scripts
- GitHub Actions workflows that affect distributed artifacts
General hardware reliability issues, unsupported platform failures, and normal camera misconfiguration are better handled through the regular issue tracker.