If you discover a security vulnerability, please:
- DO NOT open a public issue
- Email us at: security@opensin.ai
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
We will respond within 48 hours and work with you to resolve the issue.
- Never commit secrets or API keys to the repository
- Use environment variables or Infisical for all credentials
- The SecretClient (
packages/qwen-core/lib/secret-client.js) never logs secret values - Review all PRs for security implications
- Keep dependencies updated via Dependabot
| Version | Supported |
|---|---|
| 0.x.x | ✅ |