| Version | Supported |
|---|---|
Current release (0.1.x) |
Yes |
| Older, unreleased, or modified copies | No |
Security fixes target the current release and the default branch. Update to the latest supported revision before reporting behavior that may already be fixed.
Report suspected vulnerabilities privately through GitHub Security Advisories. Include the affected revision, impact, reproduction steps, and a minimal sanitized input. Do not open a public issue, publish exploit details, or include secrets or private prompt data while a report is under review.
If GitHub Security Advisories is unavailable, open a public issue that asks only for a private contact channel. Do not include vulnerability details in that issue.
Treat prompt files, JSON tool stacks, evaluation JSONL, local configuration, and gate thresholds as trusted input. The shipped tools do not intentionally execute input content or make network requests, but reports can reproduce input text, identifiers, file paths, and metric values. Do not process secrets, credentials, customer conversations, regulated data, or proprietary prompts unless your local handling and output storage are authorized.
Review generated reports before attaching them to issues or CI logs. SOL ENGINE does not provide secret scanning, access control, sandboxing, or automatic redaction.
For general contribution guidance, see CONTRIBUTING.md.