Atrium

Security policy

Report vulnerabilities privately to security@atrium-project.org. Do not open a public issue for anything with security impact.

Scope

Every repository in the atrium organization: the compositor, the shell, atrium-network, atrium-portal, atrium-setup, the package templates, and this site. A vulnerability in an upstream project atrium depends on (niri, Smithay, quickshell, wpa_supplicant, and so on) should go to that project; tell us too if atrium's use of it makes the impact worse.

What to send

Plain email is fine. If you need encryption, ask for a key in your first message.

What happens next

Safe harbour

Good-faith research against your own installation of atrium is welcome. Do not test against systems you do not own, and do not access, modify, or exfiltrate other people's data.

Machine-readable

This policy is published at /.well-known/security.txt (RFC 9116).