Skip to content

Security: toolanzyhhh1234/HELLoRA-replication

SECURITY.md

Security policy

Supported versions

The 0.1.x research-preview line receives security fixes. Unreleased code on main may change without notice.

Reporting a vulnerability

Do not open a public issue for a suspected vulnerability, leaked credential, or unsafe checkpoint-loading behavior. Use GitHub's Report a vulnerability option in the repository Security tab to submit a private report.

Include the affected revision, reproduction steps, impact, and any suggested mitigation. You should receive an initial response within seven days.

Scope

This project loads third-party model and dataset artifacts from pinned Hugging Face revisions and uses safetensors for adapter weights. It does not guarantee the security of external dependencies, model repositories, generated content, or downstream deployments. Review all artifacts and licenses before use.

There aren't any published security advisories