Skip to content

Security: Terry577/CurveAlign

SECURITY.md

Security policy

Supported version

Only the latest CurveAlign Community release is supported. Before reporting a problem, download the newest complete package from this repository, verify its published SHA-256 checksum, and reproduce it in a new folder. Do not combine a new executable with components from an older package.

Private vulnerability reports

Do not open a public Issue for a vulnerability, a way to bypass service controls, exposed credentials, or a report containing sensitive device information. Email terryliu577@gmail.com with:

  • the affected CurveAlign version;
  • the bundled Arca SMU version;
  • a concise impact description;
  • safe reproduction steps;
  • any relevant screenshot or sanitized diagnostic text.

Do not include passwords, private keys, raw hardware serial numbers, or unrelated personal files. Please allow reasonable time to investigate before publishing details.

Ordinary compatibility failures and user-support questions may use the public Issue forms after sensitive information has been removed.

There aren't any published security advisories