Skip to content

Security: mvsbm/nayose

SECURITY.md

Security policy

Supported versions

Security fixes are applied to the latest release and, when different, the current main branch. Older releases are not maintained unless a release notice explicitly says otherwise.

Reporting a vulnerability

Do not open a public issue for a suspected vulnerability or include customer data, credentials, model artifacts, or exploit details in public discussions.

Use GitHub private vulnerability reporting for this repository. If it is unavailable, contact the repository owner privately and request a secure reporting channel. Include the affected version or commit, impact, reproduction steps, and any proposed mitigation without attaching sensitive production data.

Maintainers should acknowledge a report within five business days, validate its scope, prepare a private fix, and coordinate disclosure after a patched release is available. Security fixes follow the normal audit and release gates; emergency bypasses must be documented and followed by a retrospective.

There aren't any published security advisories