Security fixes are applied to the latest commit on main. This project has not published a stable release series yet.
Use GitHub private vulnerability reporting. Do not open a public issue or include credentials, generated keys, provider payloads, traces, prompts, or customer data.
Include a synthetic reproduction, affected example, dependency versions, impact, and proposed mitigation. You can expect an acknowledgement within five business days. Disclosure timing will be coordinated after validation and remediation.
These examples require review before production use. Operators must choose model IDs, approve budgets, manage credentials, configure network exposure, verify data-retention settings, test failure behavior, and monitor upstream security releases.