Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Security policy

Report vulnerabilities privately to security@atrium-project.org. Do not open a public issue for anything with security impact.

Scope: every repository in the atrium organization. Vulnerabilities in upstream projects Atrium depends on (niri, Smithay, quickshell, wpa_supplicant, and so on) go to those projects; tell us as well if Atrium’s use of them makes the impact worse.

What to send: the affected component and version or commit, steps to reproduce or a proof of concept, what an attacker gains, and whether the report is already public. Plain email is fine; ask for a key if you need encryption.

What happens next: acknowledgement within 3 business days. A confirmed vulnerability gets a fix on master, a CVE requested through MITRE where one applies, and credit in the release notes unless you prefer otherwise. We ask for 90 days from acknowledgement before public disclosure, shorter by agreement if the fix ships sooner.

Safe harbour: good-faith research against your own installation is welcome. Do not test systems you do not own, and do not access other people’s data.

Machine-readable: atrium-project.org/.well-known/security.txt.