Security fixes are applied to the latest tagged release and main.
Do not open a public issue for secrets, command-injection paths, sandbox escapes, or unsafe circuit input handling. Use GitHub private vulnerability reporting for this repository.
Netlists, PDK maps, simulator logs, model output, archives, and benchmark inputs are untrusted. Simulator execution is allowlisted, argument-vector based, time and resource bounded, and restricted to a per-run workspace. The application must never execute model-provided shell strings or expose SSH keys, API credentials, host paths, Docker sockets, proprietary PDK files, or model weights in logs or artifacts.