Disclosure
Security
If you have found something exploitable, tell us privately first.
Reporting a vulnerability
Do not submit exploitable security vulnerabilities through the public bug tracker or the contact form. Use the dedicated security contact so a fix can be prepared before details are public.
Security contact
security@akadata.ltd
Include the affected release, the component, and enough detail to reproduce. The full process, scope and rules are described in the Responsible Disclosure policy. A machine-readable policy will be published at /.well-known/security.txt.
What we do on our side
- • The package repository is served over TLS and its indexes are signed.
- • Every published image has a SHA-256 checksum you can verify yourself.
- • Sources are pinned and hash-verified before they enter a build.
- • The installed service set is minimal: nothing runs merely because it exists.
- • Published image downloads will use short-lived authorization before the archive is served directly.
Verify a download
sha256sum -c saphira.tar.xz.sha256