Security policy
Reporting a vulnerability
Do not open a public issue for a suspected vulnerability.
Use GitHub's private vulnerability reporting for the zqk-os/zqk repository,
or email [email protected]. Include the affected version
or commit, reproduction steps, impact, and any suggested mitigation. Maintainers
will acknowledge a complete report within five business days and coordinate
disclosure after a fix is available.
Supported versions
Until the first tagged public release, security fixes apply to the current default branch only.
Automated Verification & Dependency Security
- Secret Scanning: Automated secret scanning is enforced on all pull requests and branch updates via
.github/workflows/secret-scan.ymland pre-commit checks to prevent credential leaks. - Dependency Management: Automated dependency updates and security scanning are managed through Dependabot configured for Go modules (
gomod) and GitHub Actions. - Software Bill of Materials (SBOM): Formal SBOM manifests are continuously generated and published for releases via
.github/workflows/sbom.yml.