Security
Reporting vulnerabilities
Please report potential vulnerabilities privately to maintainers.
- Do not open public issues for unpatched vulnerabilities.
- Include affected crate(s), versions, reproduction details, and impact.
- Include proof-of-concept input/trace where possible.
Workspace security scope
noxtlsnoxtls-corenoxtls-cryptonoxtls-pemnoxtls-x509noxtls-ionoxtls-platform
Policy features
Security policy and compatibility controls are implemented as compile-time features in noxtls-core:
policy-strict-constant-timepolicy-allow-legacy-algorithmspolicy-allow-sha1-signatures
Strict constant-time mode is intentionally incompatible with legacy/sha1 permissive modes.