Effectline is pre-alpha. There are no supported releases yet; until v0.1.0 is
tagged, only the latest state of the main branch is maintained.
Please do not report security issues through public GitHub issues.
Report them privately, either through GitHub private vulnerability reporting or by email to team@madeinpluto.com.
Include what you can: a description of the issue, steps to reproduce (a minimal ledger JSONL is ideal), the affected component (specification, schemas, reference implementation or CLI), and the impact you believe it has.
The project aims to acknowledge reports within seven days. Effectline is maintained by one person, so triage may take longer than in larger projects, but every report is read. There is no bug bounty program.
Effectline's core claim is that it computes the correct downstream impact set of an accepted invalidation. Anything that silently breaks that claim is treated as security-relevant, not as an ordinary bug. Examples include:
- Impact computation that omits affected records without reporting the result as incomplete or qualified.
- A partial or truncated impact computation reported as complete.
- A required resolution-conflict, partial-capture or completeness diagnostic being silently omitted.
- Digest or replay verification passing on tampered or altered records.
- Validation accepting records that the specification requires it to reject in a way that changes impact results.
- Crafted records or imports causing uncontrolled traversal, excessive resource consumption or denial of service.
Usability problems, documentation errors and crashes that cannot be triggered by untrusted input are welcome as regular public issues. Crashes, excessive resource consumption or denial of service caused by crafted records or imports should be reported privately.
A dedicated THREAT_MODEL.md covering forged invalidations, unauthorized
withdrawals, omitted edges, tampered imports and related risks will ship with
the reference implementation.
Until then, note Effectline's frozen limitations: it records declared causal
claims and cannot discover omitted ones. An incomplete ledger produces an
incomplete impact set by design, which is why capture_status and completeness
diagnostics exist.