We currently provide security updates for the latest stable release only. Older versions are not actively maintained and may contain unpatched vulnerabilities.
| Version | Supported |
|---|---|
| Latest release | ? Supported |
| Older releases | ? Not supported |
We encourage all users to keep their deployment up to date with the latest release.
We take security vulnerabilities seriously. If you discover a security issue, please report it privately before disclosing it publicly.
- Go to the Issues page
- Click "New Issue"
- Select "Report a security vulnerability" (if available)
- Provide a detailed description, including:
- The affected component and version
- Steps to reproduce the vulnerability
- Potential impact
- Any suggested mitigation (optional)
If you prefer, you can report via email:
Please do not use the public issue tracker for vulnerability reports.
After reporting a vulnerability, the following process will be followed:
- Acknowledgment ¡ª We will acknowledge receipt within 48 hours
- Investigation ¡ª We will investigate and validate the report
- Fix Development ¡ª A fix will be developed and tested
- Release & Disclosure ¡ª A patch will be released, and the vulnerability will be disclosed publicly after the fix is available
We aim to address critical vulnerabilities within 7 days of confirmation.
A PGP key for encrypted communication is not yet available. In the meantime, please use the email or GitHub Issues methods described above.
Thank you for helping keep Local AI Stack and its community safe.