Security is a first-class concern across all Nimbus projects. The full security model, threat model, invariant catalogue, and coordinated-disclosure process live in one place:
➡️ https://github.com/nimbus-agent/nimbus-security
Please do not open a public issue for security reports.
Use GitHub's private vulnerability reporting on the affected repository: its Security tab → Report a vulnerability. This is the only reporting channel — Nimbus publishes no security email address and no PGP key, because a solo maintainer's unmonitored inbox drops reports silently. Filing requires a free GitHub account.
If you are not sure which repository is affected, report it against Nimbus and we will move it.
Nimbus is maintained by one person as a side project, so there is no guaranteed response time and no SLA. Reports are typically read within a week and prioritised by severity, and we will agree a coordinated-disclosure timeline with you rather than sitting on a report. There is no bug-bounty programme.
Full policy, scope and safe-harbor terms: nimbus-security/SECURITY.md. Thank you for helping keep Nimbus and its users safe.