Skip to content

Security: caizefan34/local-ai-stack

Security

SECURITY.md

Security Policy

Supported Versions

We currently provide security updates for the latest stable release only. Older versions are not actively maintained and may contain unpatched vulnerabilities.

Version Supported
Latest release ? Supported
Older releases ? Not supported

We encourage all users to keep their deployment up to date with the latest release.

Reporting a Vulnerability

We take security vulnerabilities seriously. If you discover a security issue, please report it privately before disclosing it publicly.

Preferred Method: GitHub Private Issue

  1. Go to the Issues page
  2. Click "New Issue"
  3. Select "Report a security vulnerability" (if available)
  4. Provide a detailed description, including:
    • The affected component and version
    • Steps to reproduce the vulnerability
    • Potential impact
    • Any suggested mitigation (optional)

Alternative Method: Email

If you prefer, you can report via email:

caizefan34@outlook.com

Please do not use the public issue tracker for vulnerability reports.

What to Expect

After reporting a vulnerability, the following process will be followed:

  1. Acknowledgment ¡ª We will acknowledge receipt within 48 hours
  2. Investigation ¡ª We will investigate and validate the report
  3. Fix Development ¡ª A fix will be developed and tested
  4. Release & Disclosure ¡ª A patch will be released, and the vulnerability will be disclosed publicly after the fix is available

We aim to address critical vulnerabilities within 7 days of confirmation.

PGP Key

A PGP key for encrypted communication is not yet available. In the meantime, please use the email or GitHub Issues methods described above.


Thank you for helping keep Local AI Stack and its community safe.

There aren't any published security advisories