This policy governs security issue intake, triage, coordination, disclosure, and remediation tracking across the CommandLayer stack.
Security issues SHOULD be reported privately to the maintainers designated by organization policy. Public issue filing for unmitigated vulnerabilities MUST NOT include exploit detail.
A security report record MUST capture:
- affected repository class,
- impact statement,
- reproduction constraints,
- confidentiality requirement level,
- proposed mitigation window.
- Maintainers MUST classify severity and affected scope.
- Security-impacting fixes MUST coordinate through release policy controls in
RELEASE_POLICY.md. - Compatibility effects from security fixes MUST be recorded in compatibility artifacts.
- Public disclosure MUST occur only after mitigations are available or compensating controls are documented.
- Disclosure records MUST avoid unnecessary exploit amplification.
- Security response timelines MUST be recorded in audit or release artifacts.
Each confirmed security incident MUST produce:
- remediation record,
- policy impact review,
- audit follow-up entry in
AUDITS/.