LITHOS prioritizes the security of critical infrastructure. We currently support the following versions with security updates:
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
We appreciate the work of security researchers in identifying vulnerabilities. To ensure the safety of critical energy systems, we ask you to follow this Responsible Disclosure Policy:
- Do not open a public issue. Send reports to [SECURITY-EMAIL@DOMAIN.COM].
- Provide a detailed summary of the vulnerability, including a Proof of Concept (PoC).
- Allow the maintainers 90 days to address the issue before any public disclosure.
- We will acknowledge receipt of your report within 48 hours.
- We will provide an estimated timeline for a fix.
- We will credit you for your discovery in our security advisories (unless you prefer anonymity).