Skip to content

Security: YuLab-SMU/Rho_for_mac

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please use GitHub private vulnerability reporting for a suspected vulnerability in Rho, its release workflow, or its distributed artifacts.

Do not open a public Issue for an unpatched vulnerability. Do not include API keys, signing tokens, certificate material, personal information, private project content, or unredacted diagnostics in public Issues, pull requests, or discussion threads.

Include the affected Rho version and platform, a concise impact description, reproduction steps, and the least sensitive evidence needed to investigate. Maintainers will use the private advisory to coordinate validation, mitigation, credit, and disclosure. No fixed response or remediation deadline is promised, but reports will be handled in good faith.

For signing and release-chain behavior, see the Code signing policy. For local data and network behavior, see the Privacy policy.

Supported versions

Rho is under active development. Security fixes are made against the current development line unless a release notice explicitly identifies another supported version. Historical development artifacts may be retained as immutable evidence and should not be assumed to receive fixes.

There aren't any published security advisories