| Version | Supported |
|---|---|
| 5.1.x | ✅ |
| 5.0.x | ✅ security fixes |
| 4.0.x | |
| < 4.0 | ❌ |
Open a private report via GitHub Security Advisories:
https://github.com/Srujan0798/Adaptoid-OS/security/advisories/new
Include:
- FM number if it matches a known failure mode
- Steps to reproduce
- Impact assessment
- Suggested fix (optional)
| Severity | Acknowledgment | Fix Target |
|---|---|---|
| Critical | 24 hours | 72 hours |
| High | 48 hours | 1 week |
| Medium | 1 week | 1 month |
| Low | 1 month | Next minor release |
validators/oap_security.sh— policy enforcementvalidators/vault_mmu.sh— state integrityvalidators/publish_gate.sh— secret / embarrassment gatevalidators/route_sentinel.sh— wrong-route blocking
By default, destructive and network tool patterns ask or deny. See templates/root/policies/default.yaml.
Adaptoid is a harness kit (markdown + shell + small Python). Treat generated project policies as starting points; harden for your production blast radius.