Important
Please do not report security vulnerabilities in our public issues or discussions. That can let an attacker exploit the vulnerability before we have a chance to fix it.
The policy lives at https://knitli.com/security/. That page is canonical and carries all of it: the safe-harbor authorization for good-faith research, what is in and out of scope, the rules, how to report, what to include, our response commitments, and the coordinated-disclosure window.
- Encrypted email to
security@knitli.com. Our public PGP key is at
https://knitli.com/.well-known/pgp-key.txt (fingerprint
20D62F88EB96F19349DC093CB9635B4CC5A43E9C). - Unencrypted email if you must. Same address.
- Semaphore, but at that point just go a little further and talk to us.
The machine-readable pointer is https://knitli.com/.well-known/security.txt.
The policy used to live here in full, and a second, shorter version lived in each repository. They drifted — the numbers disagreed. Published commitments are only worth anything if there is exactly one copy of them, so there is now exactly one.
Because of that reality, if for some reason we fail to update it and the fingerprint
above doesn't match the key at https://knitli.com/.well-known/pgp-key.txt,
you should still consider it official if it verifies against security.txt.
Those are the canonical files.