interlock follows semantic versioning. Security fixes target the latest released minor of the current major.
| Version | Supported |
|---|---|
| 2.x | ✅ |
| < 2.0 | ❌ (2.0 has no breaking changes — upgrading is a version bump) |
Please do not open a public issue for security problems.
Report privately through GitHub's private vulnerability reporting, or by email to galushko355@gmail.com. Include a description, affected versions, and a reproduction if you have one.
You can expect an acknowledgement within a few days. Once a fix is ready we will release it and credit the reporter unless you prefer to stay anonymous.
The release path is auditable end to end, and the OpenSSF Scorecard badge in the README is the summary of it.
- Trusted publishing.
.github/workflows/release.ymlbuilds and publishes through PyPI's OIDC trusted publisher — there is no long-lived API token that could leak. - Signed provenance. Every artefact carries a Sigstore-backed
PEP 740 attestation generated at publish
time. PyPI serves it from
https://pypi.org/integrity/interlock-cb/<version>/<filename>/provenance. - Pinned actions. Every
uses:in.github/workflows/is pinned to a full commit SHA with the version in a trailing comment; Dependabot bumps both. - Audited workflows. zizmor runs over
.github/workflows/on every pull request, with a token so that the audits which resolve a pinned SHA against the upstream repository (impostor-commit,ref-confusion,known-vulnerable-actions,stale-action-refs) are included. Suppressions live in.github/zizmor.yml, each with a reason. - Static analysis. CodeQL default setup (
pythonandactions) plus ruff'sSruleset (flake8-bandit), which is part ofselect = ["ALL"]. - Zero-dependency core.
interlock.*imports only the standard library; every third-party library sits behind an optional extra, so the default install has no transitive attack surface.