๐Ÿ” Security Policy โ€” SemiDevKit

This document defines the security guidelines and expectations for maintaining,
distributing, and using SemiDevKit, including:

The goal is to ensure safe, predictable, and reproducible execution of semiconductor simulations and design flows.


๐Ÿšจ 1. Reporting Vulnerabilities

If you discover any security-related issues, including but not limited to:

Please report them via one of the following private channels:

๐Ÿ”’ GitHub Security Advisories
https://github.com/Samizo-AITL/SemiDevKit/security/advisories

๐Ÿ“ง Email
shin3t72@gmail.com

โš ๏ธ Do not report security issues through public GitHub Issues.


๐Ÿ›ก 2. Scope of Security Protection

Security considerations apply to all components of SemiDevKit.


๐Ÿ Python Scripts


โšก SPICE Netlists


๐Ÿณ Docker (OpenLane-Lite)


๐Ÿ“Š Data Files and Outputs


๐Ÿงฌ 3. Supported Versions

Security maintenance and fixes are provided for:

Older branches and experimental forks may not receive security updates.


๐Ÿ“ฆ 4. Dependency Security

SemiDevKit depends on the following external components:

Guidelines


๐Ÿง  5. Best Practices for Users

Running Untrusted Code


Docker Safety

When using OpenLane-Lite:

docker info

GitHub Token Safety

If interacting with GitHub Actions or APIs:


๐ŸŽฏ 6. Security Goals

SemiDevKit aims to provide:


๐Ÿ“ฌ 7. Contact

For all security-related concerns:

๐Ÿ“ง Email
shin3t72@gmail.com

๐Ÿ”’ GitHub Security Advisories
https://github.com/Samizo-AITL/SemiDevKit/security/advisories

โฑ Response Time
We aim to respond within 72 hours.


ยฉ 2025 SemiDevKit Project. All rights reserved.