No production release exists. Only the current default branch receives security fixes during the scaffold phase.
Do not open a public issue. Until a dedicated security address is configured, use a private GitHub security advisory in the official repository.
Include:
- Affected component and revision.
- Reproduction steps or proof of concept.
- Expected impact.
- Any suggested mitigation.
The project intends to acknowledge reports within three business days and provide an initial assessment within seven business days. These are targets, not contractual SLAs.
High-priority areas include authentication, authorization, signed job manifests, container isolation, update signing, node identity, model and dataset integrity, economic ledger invariants, and exposure of customer or contributor data.
Good-faith research that avoids privacy violations, service disruption, data destruction, financial harm, and public disclosure before remediation will be treated as authorized within the published testing scope.
No paid beta may launch with unresolved critical or high findings from the required independent review and penetration test.