We provide security updates for the following versions:
| Version | Supported |
|---|---|
| Latest | ✅ |
| < Latest | ❌ |
We recommend always using the latest version of our software.
Please do not report security vulnerabilities through public GitHub issues.
Instead, please report them via email to: security@singularity.example.com
You should receive a response within 48 hours. If for some reason you do not, please follow up via email to ensure we received your original message.
Please include the following information:
- Type of issue (e.g., buffer overflow, SQL injection, cross-site scripting, etc.)
- Full paths of source file(s) related to the manifestation of the issue
- The location of the affected source code (tag/branch/commit or direct URL)
- Any special configuration required to reproduce the issue
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if possible)
- Impact of the issue, including how an attacker might exploit it
- Receipt: We acknowledge receipt of your vulnerability report
- Assessment: We assess the vulnerability and determine severity
- Fix: We develop and test a fix
- Disclosure: We coordinate disclosure with you
- Release: We release the security update
- Credit: We credit you in the security advisory (unless you prefer to remain anonymous)
All Singularity projects include:
- Automated security audits -
cargo auditruns on every release - Dependency checking -
cargo denyvalidates all dependencies - SBOM generation - Complete dependency transparency
- Zero warnings tolerance - Strict linting catches potential issues
- Regular updates - Renovate keeps dependencies current
When using Singularity software:
- Keep updated - Always use the latest version
- Review dependencies - Check the SBOM in releases
- Enable security features - Use all available security options
- Follow principle of least privilege - Run with minimal permissions
- Monitor security advisories - Watch the repository for updates
- Security issues: security@singularity.example.com
- General questions: See SUPPORT.md
Thank you for helping keep Singularity and our users safe!