Security fixes are currently provided for the latest release on main. Version 0.2 is alpha software and has not undergone an independent security audit.
Please use GitHub's private vulnerability reporting for issues that could expose data, escape an output directory, execute unintended code, or corrupt a registry without detection. Do not include secrets or sensitive benchmark data in a public issue. Use a regular bug report for non-sensitive correctness failures.
Include the affected version, operating system, minimal input, exact command, observed behavior, and expected trust boundary. Maintainers will acknowledge a well-formed report when available; no fixed response-time SLA is promised.
EvalAudit uses safe YAML loading and does not execute code referenced by an audit declaration. Report bundles and registries should still be treated as untrusted. Verify bundles before consuming them, and anchor registry head hashes in reviewed Git history or another trusted channel.