CI / rustfmt (push) Waiting to run
CI / clippy --all-features (push) Waiting to run
CI / test (default) (push) Waiting to run
CI / test (parallel) (push) Waiting to run
CI / test (serde) (push) Waiting to run
CI / test (serde,parallel) (push) Waiting to run
CI / cargo doc (push) Waiting to run
CI / minimum supported Rust version (1.85) (push) Waiting to run
CI / fuzz smoke (clamp_to_bounds) (push) Waiting to run
CI / fuzz smoke (crowding_distance) (push) Waiting to run
CI / fuzz smoke (hypervolume_2d) (push) Waiting to run
CI / fuzz smoke (non_dominated_sort) (push) Waiting to run
CI / fuzz smoke (pareto_archive) (push) Waiting to run
CI / fuzz smoke (pareto_compare) (push) Waiting to run
CI / fuzz smoke (sbx_polymut) (push) Waiting to run
CI / fuzz smoke (spacing) (push) Waiting to run
Docs / Build mdbook (push) Waiting to run
Docs / Deploy to GitHub Pages (push) Blocked by required conditions
Rewrites lingering github.com / *.sr.ht references to this Gitea instance, translating GitHub and Sourcehut URL shapes to Gitea's (/blob/<ref>/ and sr.ht /tree/<ref>/item/ -> /src/branch/<ref>/, /tree/<tag> -> /src/tag/<tag>, /actions/workflows/X -> /actions?workflow=X, /edit/ -> /_edit/). Left pointing at the old hosts on purpose: pull-request links (PRs were not migrated), forks that were never migrated, and GitHub-only surfaces Gitea lacks. OpenPGP identity proofs are untouched by design.
2.2 KiB
2.2 KiB
Security policy
Supported versions
Security fixes are applied to the latest released minor version on
crates.io. Patch-level releases (0.x.y → 0.x.y+1) are issued as
needed.
| Version | Supported |
|---|---|
| 0.10.x | ✅ |
| ≤ 0.9.x | ❌ (please upgrade) |
heuropt is pre-1.0; the public API may change between minor versions. Once 1.0.0 ships, the support window will be at least the latest two minor versions.
Reporting a vulnerability
Please do not open a public issue for a security bug. Instead:
- Email steve@waits.net with subject line
[heuropt security] <short summary>.
(This project is hosted on git.swaits.com, which has no private-advisory feature, so email is the reporting channel.)
Please include:
- A description of the vulnerability and the affected versions.
- The smallest reproducer you can produce — a
cargo run --example reprois ideal. - Your assessment of impact and exploitability.
- Any suggested mitigation if you have one.
What I will do
- Acknowledge the report within 72 hours.
- Confirm or refute reproducibility within 7 days.
- Issue a fix in a patch release within 30 days for confirmed high-severity issues; less urgent issues may roll into the next minor release.
- Credit the reporter in the CHANGELOG entry unless you ask otherwise.
What counts as a security issue
heuropt is a numerical library, not a network service or sandbox. The realistic security-relevant categories are:
- Memory safety: any unsafe-code-related UB or unwinds-across-FFI
bug. heuropt itself uses no
unsafe; this category covers dependencies it transitively pulls in. - Denial of service: an input to a public API that causes unbounded memory growth, infinite loop, or panic outside its documented panic conditions. (Documented panics for invalid config are not bugs.)
- Supply-chain compromise: a published heuropt crate that doesn't match the source on the tagged commit.
Functional correctness bugs (an algorithm produces wrong hypervolumes, etc.) are tracked as ordinary issues, not security.