Skip to content

Security: lima-vm/lima

SECURITY.md

Reporting security issues

To report security issues, use GitHub Security Advisories (GHSA) forms such as https://github.com/lima-vm/lima/security/advisories/new .

If you do not have a GitHub account, you may use email to reach out to the Committers directly. See the GitHub profiles or the git commit logs to inspect the Committers' email addresses.

Handling security issues

The Committers will try to triage the report and make the first response within 7 days. Releasing a fix may take a longer time, and may need further assistance from the reporter.

If you do not see any response after 7 days, ping the Committers via email or Slack privately.

Learn more about advisories related to lima-vm/lima in the GitHub Advisory Database