Skip to content

Security: QinXi-ai/evalspec-audit

SECURITY.md

Security policy

Supported version

Security fixes are currently provided for the latest release on main. Version 0.2 is alpha software and has not undergone an independent security audit.

Reporting

Please use GitHub's private vulnerability reporting for issues that could expose data, escape an output directory, execute unintended code, or corrupt a registry without detection. Do not include secrets or sensitive benchmark data in a public issue. Use a regular bug report for non-sensitive correctness failures.

Include the affected version, operating system, minimal input, exact command, observed behavior, and expected trust boundary. Maintainers will acknowledge a well-formed report when available; no fixed response-time SLA is promised.

Input safety

EvalAudit uses safe YAML loading and does not execute code referenced by an audit declaration. Report bundles and registries should still be treated as untrusted. Verify bundles before consuming them, and anchor registry head hashes in reviewed Git history or another trusted channel.

There aren't any published security advisories