Skip to content

Security: dev-boffin-io/llama-forge

Security

SECURITY.md

πŸ”’ Security Policy β€” llama-forge


Scope

This security policy applies to the llama-forge GUI frontend (llama_gui/) and the build system maintained in this fork.

For security vulnerabilities in the upstream llama.cpp inference engine, please report directly to ggml-org/llama.cpp.


Supported Versions

Version Supported
Latest master βœ… Yes
Older commits ❌ No

Reporting a Vulnerability

Please do not open a public GitHub Issue for security vulnerabilities.

Report privately via email:

πŸ“§ tradeguruboffin@gmail.com

What to Include

  • A clear description of the vulnerability
  • The component affected (llama_gui/, build system, etc.)
  • Steps to reproduce
  • Potential impact and severity assessment
  • Any suggested fix (optional but appreciated)

Response Timeline

Stage Timeline
Acknowledgement Within 72 hours
Initial assessment Within 7 days
Fix release (if confirmed) Within 14 days

Disclosure Policy

We follow responsible disclosure. Please allow us time to investigate and release a fix before making any vulnerability public.


Out of Scope

  • Vulnerabilities in upstream llama.cpp (report to ggml-org)
  • Issues requiring physical access to the device
  • Social engineering attacks
  • PyQt6 or Qt framework vulnerabilities (report to the Qt Project)

There aren't any published security advisories