Security reports are assessed against the latest released version and the
current main branch. The first supported release is v0.1.0.
Please do not include exploitable details in a public issue, discussion, or pull request. Use the repository's private vulnerability-reporting feature on GitHub when it is available. If it is unavailable, open a minimal public issue requesting a private contact channel without describing the vulnerability.
Include, where safe to share:
- the affected revision or build;
- operating system and command used;
- a minimal reproduction and expected security boundary;
- impact, prerequisites, and any suggested mitigation.
Reports concerning model downloads, checksum verification, cache handling, local file processing, bundled native dependencies, or command-line argument handling are all in scope. Do not attach secrets, private model files, or unredacted production logs.
Maintainers will acknowledge reports and coordinate a fix or disclosure on a best-effort basis. Please allow time for investigation before public disclosure.