Do not open a public issue for security reports.
Preferred channel: open a private advisory at https://github.com/xberg-io/liter-llm/security/advisories/new.
Alternative: email security@xberg.io.
Please include a description of the issue, steps to reproduce, affected versions, and your preferred credit (or none). We acknowledge reports within 2 business days and aim to publish a fix within 14 days for critical issues and 30 days for others.
Security fixes target the latest release on main. Older versions are not back-ported.
In scope: the liter-llm library and its bindings. Out of scope: third-party LLM provider APIs (report upstream and notify us).