Security

For the protection of our community, the Pkl team does not disclose, discuss, or confirm security issues until our investigation is complete and any necessary updates are generally available.

Reporting a security vulnerability

If you have discovered a security vulnerability within the Pkl project, please report it to us. We welcome reports from everyone, including security researchers, developers, and users.

If you believe that you have discovered a security vulnerability in our open source software, please report it to us using the GitHub private vulnerability feature. This can be done by navigating to the "Security" tab of the specific repository where you found the issue. For other Apple software, please report a security or privacy vulnerability on Apple Security Research.

If you are not certain if something counts as a security vulnerability, you can review our threat model, paying attention to the out-of-scope items.