Feather has no published or hardware-supported release yet.
| Version | Security status |
|---|---|
| Default development branch | Reports accepted on a best-effort basis |
| Untagged local/CI images | Unsupported; reproduce against the source commit |
| Future releases | Policy will identify supported lines before publication |
Debian packages in an installed system receive updates from Debian's signed repositories. That does not make an untagged Feather image a supported release.
Do not open a public issue for a suspected vulnerability.
Email the maintainer privately at
saketh.sripada@gmail.com with the subject
[Feather Security] <short description>.
GitHub private vulnerability reporting for this repository returned unavailable during the 2026-07-23 policy check. When the repository host enables it, this document will link the repository-specific advisory form and make it the preferred route. The generic GitHub documentation is not presented as if that feature were already configured.
Include:
- affected source commit and, if relevant, ISO SHA-256;
- affected component and trust boundary;
- minimal reproduction steps;
- realistic impact and required privileges;
- whether the issue is public elsewhere;
- a safe way to contact you.
Do not send passwords, private keys, Wi-Fi credentials, enrollment tokens, DMI serial numbers, personal files, or a live exploit against a physical device. If email metadata is itself sensitive, send a minimal initial report and agree on a safer transfer method before sharing evidence.
An initial acknowledgement is targeted within seven days. Triage will establish scope, affected versions, disclosure coordination, and whether the fix belongs in Feather or upstream. No resolution deadline is promised before impact and upstream dependencies are understood.
Report issues here when they involve project-owned behavior, including:
- build/provenance substitution or executing unreviewed dependency content;
- QEMU harness escapes from its qcow2/path safety boundary;
- Calamares privilege, target-root, disk-selection, or cleanup behavior;
- exact-board detection selecting the wrong profile;
- hardware integration escaping its target root or network-free contract;
- dangerous speaker configuration being applied automatically;
- live-only autologin or passwordless policy persisting after installation;
- update configuration, bootloader fallback, or generated image integrity.
- Vulnerabilities in an unmodified Debian package should be reported through the Debian security process. Also notify Feather when its defaults or image composition materially increase impact.
- Vulnerabilities in pinned third-party source should be reported privately to that upstream when it has a security route. Notify Feather so the pin, allowlist, or integration can be contained.
- MrChromebox firmware, ChromeOS, embedded-controller firmware, and hardware defects are not maintained by Feather. Use the relevant vendor/upstream security channel.
- Enterprise enrollment, ownership controls, and Verified Boot policy are not Feather features to bypass. Requests or techniques for bypassing them are out of scope.
- General support, installation failures, and feature requests belong in the normal issue templates unless they expose a security boundary.
Feather will coordinate a fix, dependency pin, advisory, artifact withdrawal, and credit where appropriate. Public disclosure should wait until affected users have a reasonable mitigation path.