Research preview · 0.1.0-draft

No compatibility guarantee. Not for consequential production decisions.

Informative View tagged source

Security policy

On this page

Research-preview support

0.x drafts are not supported for consequential production use. The project does not currently provide security or compatibility service-level guarantees.

Reporting a vulnerability

Do not open a public issue for a vulnerability that could expose data, bypass validation, cause resource exhaustion, execute untrusted content, forge provenance, or confuse conformance with authorization.

Use GitHub's private vulnerability reporting for this repository (Security -> Report a vulnerability), or open a minimal non-sensitive issue asking a maintainer to establish a private channel. Include:

  • affected draft or artifact;
  • minimal reproduction;
  • expected and actual behavior;
  • likely impact;
  • whether the issue is already public; and
  • any suggested mitigation.

Do not include customer packs, credentials, or other sensitive data in a report.

Security boundary

A conforming document is untrusted input. Implementations should bound bytes, nesting, collection sizes, string lengths, reference work, and evaluation work. Validators must not fetch locators, execute extension content, or grant operational authorization merely because a document conforms.