Skip to content

Security: ReFineID/refineid-core

SECURITY.md

Security policy

ReFineID handles card credentials and retry-limited operations. Please report security issues privately through GitHub's Report a vulnerability action on the repository Security tab. Do not open a public issue for a suspected secret leak, credential-handling flaw, card-lockout risk, or signature bypass.

Never include a real PIN, PUK, private key, personal identity code, certificate private material, or raw credential APDU in a report. Use structural descriptions and synthetic values. Maintainers can arrange a safer evidence transfer when needed.

The public tree is pre-release. No released version is currently designated as security-supported.

There aren't any published security advisories