Security fixes are applied to the latest published EvalSeal release.
| Version | Supported |
|---|---|
| 0.1.x | Yes |
Report suspected vulnerabilities through GitHub's private vulnerability reporting for this repository. If the private form is unavailable, open a public issue requesting a private contact channel without including vulnerability details. Do not include exploit details, sensitive evidence, or candidate data in a public issue.
Include the affected version, impact, reproduction steps, and any suggested mitigation. The maintainer will acknowledge the report, assess severity, and coordinate disclosure and a fix through the private report.
EvalSeal validates supplied records and local file relationships. Reports about false or misleading evidence should identify a deterministic validation rule the gate could enforce; the gate cannot independently establish that an external report is truthful.