Please report security issues privately — do not open a public issue for a vulnerability.
Use GitHub's private vulnerability reporting: Report a vulnerability (Security → Advisories → Report a vulnerability on the repository).
Include, as far as you can: the affected version, the platform (Windows / Linux / macOS), a description of the issue, and a minimal reproduction. You can expect an acknowledgement within a few days; a fix and coordinated disclosure follow once the issue is confirmed.
processkit manages process trees and touches privileged OS surfaces — Windows
Job Objects, Linux cgroup v2, POSIX process groups, and on Unix it can
drop privileges (uid/gid/supplementary groups/setsid). Bugs in these
paths can have safety or isolation consequences (a leaked subprocess, an incomplete
privilege drop, a containment escape), so they are treated as security issues, not
just functional ones.
If you're launching a program you don't trust, read Running untrusted children first: it lays out what this crate does and does not guarantee (it hardens process management, it is not a sandbox — seccomp/AppContainer/namespaces/a real OS container remain the caller's job) and the concrete checklist for containment, resource limits, privilege drop, and environment hygiene.
Security fixes land on the latest published version on
crates.io; please reproduce on the latest
release before reporting. Within the current 2.x line, fixes ship as patch
releases.
Releases are published to crates.io with Trusted Publishing: the release workflow mints a short-lived token over GitHub OIDC for that run and never stores a long-lived crates.io API token. If the token cannot be minted, the release fails rather than silently falling back to a stored secret.
Each release also carries a build-provenance attestation for the packaged
.crate (and its SHA256SUMS), signed during the same run. This binds the
artifact to this repository and its release.yml workflow, so you can confirm
what you install was built here and not tampered with. See
Verifying provenance in the README for the
exact gh attestation verify command.