Security¶
Security Policy¶
Supported versions¶
openauc-io is in alpha development. 0.1.0a1 is the first public
release, and there is no supported release line yet: security fixes are applied
to the main branch and reach users in the next release, not as patches to
0.1.0a1. This section will be updated when a supported line exists.
Reporting a vulnerability¶
Please report suspected vulnerabilities privately. Do not open a public issue for a security problem.
- Preferred: open a private advisory via GitHub Security Advisories ("Report a vulnerability") at https://github.com/ronfinn/openauc-io/security/advisories/new.
Please include a description, reproduction steps, affected version/commit, and any relevant environment details. We will acknowledge your report and keep you informed of progress toward a fix.
Scope note¶
openauc reads external data files (CSV/TSV, manifests, and .aucx archives).
Reports about parsing untrusted input — for example resource exhaustion or
unsafe deserialization — are in scope and welcome.
What openauc does defensively¶
Archives¶
Reading an .aucx file rejects, before allocating anything:
- absolute member paths,
..traversal and backslash-separated names; - duplicate member names;
- encrypted members;
- members declaring more than 512 MiB, or 2 GiB in total.
Arrays are loaded with allow_pickle=False and object arrays are rejected, so
reading an archive can never execute code. Archives are never extracted to
disk.
Manifests¶
data_file must be a safe relative path. Absolute paths, .. and drive-letter
forms are rejected, so a manifest cannot reach outside its own directory.
Checksums¶
Every archive member except the checksum file is checksummed, and every digest is verified before any model is constructed.
Integrity, not authenticity
A verified archive is one whose bytes are unchanged since it was written. SHA-256 here proves nothing about who wrote it. AUCX carries no signature, and signing is out of scope for version 1.0.
Do not treat a passing archive as evidence of origin, authorship or approval.
Reporting a problem¶
Use the process in SECURITY.md above. Please include the openauc version
(openauc version), the platform, and a synthetic reproduction — never
attach real or confidential experimental data.