Do not open a public issue for vulnerabilities that could expose users, partners, or private code.
Report privately to the current maintainer:
- Maintainer: Hugo Payet
- Contact: replace this line with the private security email before publishing the repository broadly.
Include:
- affected commit, tag, or binary version;
- reproduction steps;
- input files or sanitized proof of concept;
- expected and observed behavior;
- impact assessment if known.
| Step | Target |
|---|---|
| Acknowledge report | 5 business days |
| Initial triage | 10 business days |
| Remediation plan | After triage, based on severity |
| Public disclosure | After fix or coordinated disclosure agreement |
The project is currently pre-1.0. Security fixes are handled on the active development branch and latest release artifacts.
Security reports, unpublished analyzer rules, model internals, partner findings, and proof-of-concept inputs are controlled or restricted material. Do not publish them before triage and approval.