Security fixes are provided for the latest release of veritas-leakage.
Please do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting to share reproduction details and impact privately. You should receive an initial response within five business days.
Never include API keys, private benchmark contents, or other secrets in a report.
The hosted browser audit accepts bring-your-own provider credentials for a single request. Veritas application code keeps the credential in request memory only and does not serialize it into reports, caches, cookies, browser storage, or application logs. Provider prompts and credentials are still transferred over HTTPS to the selected provider and remain subject to that provider's policies.