Security policy
Report vulnerabilities privately to security@atrium-project.org. Do not open a public issue for anything with security impact.
Scope
Every repository in the atrium organization: the compositor, the shell, atrium-network, atrium-portal, atrium-setup, the package templates, and this site. A vulnerability in an upstream project atrium depends on (niri, Smithay, quickshell, wpa_supplicant, and so on) should go to that project; tell us too if atrium's use of it makes the impact worse.
What to send
- The affected component and version or commit.
- Steps to reproduce, or a proof of concept.
- What an attacker gains: local privilege, another user's session, arbitrary code, denial of service.
- Whether the report is already public anywhere.
Plain email is fine. If you need encryption, ask for a key in your first message.
What happens next
- Acknowledgement within 3 business days.
- A confirmed vulnerability gets a fix on
master, a CVE requested through MITRE where one applies, and a note in the affected repository's release notes crediting the reporter unless they prefer otherwise. - We ask for 90 days from acknowledgement before public disclosure, shorter by agreement if the fix ships sooner.
Safe harbour
Good-faith research against your own installation of atrium is welcome. Do not test against systems you do not own, and do not access, modify, or exfiltrate other people's data.
Machine-readable
This policy is published at /.well-known/security.txt (RFC 9116).