Loading…
Last updated: 2026-06-03.
Please disclose vulnerabilities privately to security@niso.online. We aim to acknowledge within 48 hours and ship a fix or mitigation within 14 days for critical issues.
Do not file public GitHub issues or post on social media until we've confirmed a coordinated disclosure window.
niso.online — this websiteregistry.niso.online — the package registry APIniso-cli, niso-registry and other niso cratesOut of scope: third-party packages published by independent authors under their own namespaces. Report those to the author directly.
.niso package. The client verifies it on pull and aborts on mismatch.niso-pack; signature verification is enforced by the client when a public key is registered for the namespace.We don't currently run a formal bug bounty programme, but verified critical reports will receive public credit (with your consent) and a small thank-you (swag, CVE coordination support).