Skip to content

Security: eraflo/Calcine

Security

SECURITY.md

Security policy

Calcine exposes a local HTTP API (127.0.0.1:18181) that runs models on your machine. We take issues that could let a web page, another program, or a remote host reach that API, read local files, or tamper with updates seriously.

Supported versions

Version Supported
Latest stable release (main) ✅
Latest beta (dev) ✅ best effort
Older releases ❌

Reporting a vulnerability

Please do not open a public issue. Report it privately through GitHub private vulnerability reporting ("Security" tab → "Report a vulnerability").

Include the Calcine and GenieX versions, your OS, steps to reproduce, and the impact you observed. We aim to acknowledge reports within 72 hours and to ship a fix for confirmed high-severity issues within 14 days.

Vulnerabilities in GenieX itself should be reported to qualcomm/GenieX.

There aren't any published security advisories