Skip to content

Security: tawAsh1/batchkoi

SECURITY.md

Security Policy

Reporting a vulnerability

Please report vulnerabilities privately via GitHub private vulnerability reporting — do not open a public issue. You should get a first response within a week.

Supported versions

Only the latest release receives security fixes.

Supply chain

  • Release binaries are built by GitHub Actions from a v* tag, with build provenance attestations. Verify a download with:

    gh attestation verify batchkoi_*.tar.gz --repo tawAsh1/batchkoi
  • All workflow actions are pinned to full commit SHAs; dependency updates go through Dependabot with a 7-day cooldown.

There aren't any published security advisories