SkeinDB is a fast-moving prototype. Security fixes are applied to the main
branch and included in the next tagged release. Always test against the latest
release before reporting.
Please do not open a public issue for security problems.
Use GitHub's private vulnerability reporting:
- Go to the Security advisories page.
- Describe the issue, affected surface (SkeinQL / MySQL / PostgreSQL / SkeinAdmin / storage), and a minimal reproduction.
- Include the version string from
system.versionor the SkeinAdmin Version button.
We aim to acknowledge reports within a few business days. Once a fix is available, we will coordinate a disclosure timeline with you.
In scope:
- The
skeindbbinary and its protocol surfaces (SkeinQL, MySQL, PostgreSQL, HTTP). - The embedded SkeinAdmin console.
Out of scope:
- Issues that require a pre-compromised host or operator credentials.
- Denial of service from intentionally pathological local configuration.