| Version | Supported |
|---|---|
| 0.1.x | ✓ |
Do not open a public GitHub issue for security vulnerabilities.
Report vulnerabilities via one of these private channels:
- Email: dieterolson@gmail.com
- GitHub private reporting: Security advisories
Include:
- A description of the vulnerability and its potential impact
- Steps to reproduce or a proof-of-concept
- Maxwell-Daemon version and Python version
- Any suggested mitigations
You can expect an acknowledgement within 48 hours and a status update within 7 days. If a fix is warranted, we will coordinate a disclosure timeline with you before publishing anything publicly.
In scope: the maxwell_daemon Python package and its direct dependencies as shipped.
Out of scope: vulnerabilities in LLM provider APIs (Anthropic, OpenAI, etc.) — report those directly to the respective vendor.