zhi

Security Policy

Security is a core principle of zhi – it’s right there in the name (智 – wisdom). We take vulnerability reports seriously and appreciate the community’s help in keeping the project safe.

Supported Versions

Version Supported
main (development) Yes

As the project matures and tagged releases are published, this table will be updated to reflect which versions receive security fixes.

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Instead, report them privately using one of the following methods:

  1. GitHub Security Advisories (preferred) – Open a private security advisory directly on this repository.
  2. Email – reach out to the maintainer at the email address listed on their GitHub profile.

What to include

What to expect

Security Design

zhi is built with security in mind from the ground up:

Scope

The following are in scope for security reports:

The following are out of scope:


A wise Trainer secures their Pokedex before venturing into tall grass. Thank you for helping us keep zhi safe.