Skip to content
saphiralinux

Disclosure

Security

If you have found something exploitable, tell us privately first.

Reporting a vulnerability

Do not submit exploitable security vulnerabilities through the public bug tracker or the contact form. Use the dedicated security contact so a fix can be prepared before details are public.

Security contact
security@akadata.ltd

Include the affected release, the component, and enough detail to reproduce. The full process, scope and rules are described in the Responsible Disclosure policy. A machine-readable policy will be published at /.well-known/security.txt.

What we do on our side

  • • The package repository is served over TLS and its indexes are signed.
  • • Every published image has a SHA-256 checksum you can verify yourself.
  • • Sources are pinned and hash-verified before they enter a build.
  • • The installed service set is minimal: nothing runs merely because it exists.
  • • Published image downloads will use short-lived authorization before the archive is served directly.

Verify a download

sha256sum -c saphira.tar.xz.sha256