Debuglet is an alpha intended for trusted environments. The versioned threat model describes actors, trust boundaries and current limitations. The Security and supported scope Wiki page contains operator guidance.
The latest release and the current validated main commit are supported. Security fixes are not backported. Record the package version and source revision when reporting an issue.
See Versions and compatibility for the tested combinations and how protocol, API, guest ABI, and state versions differ.
Do not disclose vulnerability details, credentials, private keys, or exploit material in a public issue or pull request.
Use GitHub private vulnerability reporting when it is available. Otherwise, open a public issue titled Security reporting contact request without technical details and ask a maintainer for a private reporting channel.
A useful private report includes the affected version, deployment profile, minimal reproduction, impact, and expected behavior. Remove credentials and other sensitive data before sharing logs or attachments.