Security · VNX-DNA 9.0.0
Security
Containers are sealed with AES-256-GCM; --key-file is checked on full decode; --max-container-bytes bounds what a forged superblock may claim; --expect-archive-id / --expect-sha256 bind a decode to a known archive. Parsers and native kernels are fuzzed (libFuzzer, hypothesis) and built with ASan/UBSan in CI. VNX-Secure adds a policy-controlled control plane: see VNX-Secure. Report vulnerabilities via Security.
Last updated 2026-10-08