Security fixes are applied to the current default branch. Archived versions are not patched.
Please do not open a public issue for security problems.
Use GitHub's private reporting channel: Security → Report a vulnerability (https://github.com/agi-research/security/advisories/new), or contact the maintainer directly.
Please include:
- what the issue is and which component is affected
- steps to reproduce, or a proof-of-concept
- the impact you believe it has
A human-readable acknowledgement within a few business days, best effort. Triage and a fix timeline depend on severity; no SLA is promised. Confidentiality is maintained for reporters throughout.
This repository is a research artifact: code, data, and pre-registration documents. Reports about dependencies with a published CVE are welcome and will be tracked; issues in upstream services are out of scope.
Reports about the integrity of published evidence, hashes, or manifests are valued: the repositories here carry SHA-256 manifests, and a broken recomputation is a security issue too.