Skip to content

Security: santho090/inference-bottleneck-lab

Security

SECURITY.md

Security policy

Supported version

Security fixes are made on the latest released version.

Reporting a vulnerability

Do not include credentials, production traces, customer data, or confidential infrastructure details in a public issue. Use the repository’s private security-reporting channel when one is configured; otherwise, contact the current project maintainers through the repository contact listed by the hosting service.

Provide a minimal synthetic reproducer where possible, affected version, impact, and steps to reproduce. The project is an offline analyzer; reports involving an explicitly supplied metrics URL should include URL behavior without sharing a sensitive endpoint.

Scope notes

  • ibl adapt --url is read-only, follows no redirects, rejects URL credentials, uses a timeout, and limits response bytes.
  • The tool does not persist input URLs, credentials, or fetched bodies outside its requested output.
  • User-supplied traces remain outside version control.

There aren't any published security advisories