| Version | Supported |
|---|---|
| 0.1.x | ✅ Yes |
Please do NOT report security vulnerabilities through public GitHub Issues.
Security issues reported publicly can be exploited before a fix is available.
Open a private GitHub Security Advisory:
- Go to the Security tab of this repository
- Click "Report a vulnerability"
- Fill in the details
Or contact the maintainer directly via GitHub.
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Your suggested fix (if any)
| Step | Timeline |
|---|---|
| Acknowledgement | Within 72 hours |
| Assessment | Within 7 days |
| Fix timeline communicated | Within 14 days |
| Credit given | In release notes |
Security concerns include:
- Authentication bypass
- JWT vulnerabilities
- SQL injection
- Prompt injection at system level
- API key exposure
- Dependency vulnerabilities (CVEs)
- AI model hallucinations (not a security issue)
- Slow response times
- Feature requests