Please do NOT open public GitHub issues for security vulnerabilities.
To report a security issue, follow the Red Hat security reporting process:
- Email: secalert@redhat.com
- Details: https://access.redhat.com/security/team/contact
Alternatively, use GitHub's private vulnerability reporting on this repository ("Report a vulnerability" under the Security tab) if it is enabled for your account.
Please include:
- The affected component and commit or release tag
- A description of the issue and its impact
- Reproduction steps or a proof of concept where possible
This policy covers the traust security assessment harness (skills, schemas, prompts, and CLI).
Only the current main branch receives security fixes.