mosaic

Security Policy

Supported Versions

Mosaic is currently pre-1.0. Security fixes target the default branch unless a release branch is explicitly maintained.

Reporting a Vulnerability

Please do not open a public issue for sensitive security reports.

Send a private report to the maintainer with:

If private contact details are not available, open a minimal public issue that asks for a private security contact without disclosing exploit details.

Scope

Relevant security issues may include:

Out of scope:

Operational Guidance

Mosaic invokes external FFmpeg and FFprobe binaries. Applications using Mosaic should:

Dependency Updates

The Go module currently has no third-party Go dependencies. Keep the Go toolchain and FFmpeg installation current in deployment environments.