Skip to content

Security: dragonflylonghk-code/MemoryValidator-OSS

Security

SECURITY.md

Security Policy

Current support

This repository is a local Windows x64 MVP. Supported repository surfaces are the v0.1 Core contracts; read-only hardware, Windows validation, and optional user-supplied smartctl adapters; completed llama-bench JSON import; deterministic diagnostic correlation; and privacy-safe JSON/Markdown reporting through the CLI. There is no network service, telemetry, updater, dynamic plugin, arbitrary tool runner, remediation executor, or tuning component.

Reporting

Do not include secrets, personal identifiers, machine-unique identifiers, private artifacts, or exploit payloads in a public report. Until a dedicated private reporting channel is published, open a minimal public issue that asks maintainers for a secure contact method without disclosing sensitive details.

Permanent boundaries

  • No silent telemetry, analytics, or upload.
  • No TLS or certificate-validation bypass.
  • No BIOS, SPD, SMBus, voltage, FCLK, UCLK, timing, Ring0, or kernel-driver writes.
  • No hostname, username, IP, MAC, MachineGuid, disk serial, Windows key, or email in identity material.
  • No raw serial, personal path, remote/RPC endpoint, stderr, exception, credential, or secret in persistent CLI reports.
  • No UNC, network-drive, device-namespace, URI, or reparse-point file access through the CLI.
  • No stale-generation mutation of committed authority.
  • No interpretation of tool/process failure as hardware failure without independent diagnostic evidence.
  • No push, publish, release, or remote configuration without explicit authorization.

All future adapters must live outside the Core contract namespaces, consume the published contracts, and fail closed at their trust boundaries.

There aren't any published security advisories