Security is a first-class concern across all Nimbus projects. The full security model, threat model, invariant catalogue, and coordinated-disclosure process live in one place:
➡️ https://github.com/nimbus-agent/nimbus-security
Please do not open a public issue for security reports.
Instead, use GitHub's private vulnerability reporting on the affected repository (the Security tab → Report a vulnerability), or follow the disclosure instructions in the nimbus-security repository.
We aim to acknowledge reports within a few business days and will coordinate a fix and a disclosure timeline with you. Thank you for helping keep Nimbus and its users safe.