Skip to content

Security: SakethSripada/Feather-Linux

Security

SECURITY.md

Security policy

Supported versions

Feather has no published or hardware-supported release yet.

Version Security status
Default development branch Reports accepted on a best-effort basis
Untagged local/CI images Unsupported; reproduce against the source commit
Future releases Policy will identify supported lines before publication

Debian packages in an installed system receive updates from Debian's signed repositories. That does not make an untagged Feather image a supported release.

Reporting a vulnerability

Do not open a public issue for a suspected vulnerability.

Email the maintainer privately at saketh.sripada@gmail.com with the subject [Feather Security] <short description>.

GitHub private vulnerability reporting for this repository returned unavailable during the 2026-07-23 policy check. When the repository host enables it, this document will link the repository-specific advisory form and make it the preferred route. The generic GitHub documentation is not presented as if that feature were already configured.

Include:

  • affected source commit and, if relevant, ISO SHA-256;
  • affected component and trust boundary;
  • minimal reproduction steps;
  • realistic impact and required privileges;
  • whether the issue is public elsewhere;
  • a safe way to contact you.

Do not send passwords, private keys, Wi-Fi credentials, enrollment tokens, DMI serial numbers, personal files, or a live exploit against a physical device. If email metadata is itself sensitive, send a minimal initial report and agree on a safer transfer method before sharing evidence.

An initial acknowledgement is targeted within seven days. Triage will establish scope, affected versions, disclosure coordination, and whether the fix belongs in Feather or upstream. No resolution deadline is promised before impact and upstream dependencies are understood.

Feather security scope

Report issues here when they involve project-owned behavior, including:

  • build/provenance substitution or executing unreviewed dependency content;
  • QEMU harness escapes from its qcow2/path safety boundary;
  • Calamares privilege, target-root, disk-selection, or cleanup behavior;
  • exact-board detection selecting the wrong profile;
  • hardware integration escaping its target root or network-free contract;
  • dangerous speaker configuration being applied automatically;
  • live-only autologin or passwordless policy persisting after installation;
  • update configuration, bootloader fallback, or generated image integrity.

Upstream and out-of-scope boundaries

  • Vulnerabilities in an unmodified Debian package should be reported through the Debian security process. Also notify Feather when its defaults or image composition materially increase impact.
  • Vulnerabilities in pinned third-party source should be reported privately to that upstream when it has a security route. Notify Feather so the pin, allowlist, or integration can be contained.
  • MrChromebox firmware, ChromeOS, embedded-controller firmware, and hardware defects are not maintained by Feather. Use the relevant vendor/upstream security channel.
  • Enterprise enrollment, ownership controls, and Verified Boot policy are not Feather features to bypass. Requests or techniques for bypassing them are out of scope.
  • General support, installation failures, and feature requests belong in the normal issue templates unless they expose a security boundary.

Feather will coordinate a fix, dependency pin, advisory, artifact withdrawal, and credit where appropriate. Public disclosure should wait until affected users have a reasonable mitigation path.

There aren't any published security advisories