Skip to content

Security: jonathanjasare/evalseal

SECURITY.md

Security policy

Supported versions

Security fixes are applied to the latest published EvalSeal release.

Version Supported
0.1.x Yes

Reporting a vulnerability

Report suspected vulnerabilities through GitHub's private vulnerability reporting for this repository. If the private form is unavailable, open a public issue requesting a private contact channel without including vulnerability details. Do not include exploit details, sensitive evidence, or candidate data in a public issue.

Include the affected version, impact, reproduction steps, and any suggested mitigation. The maintainer will acknowledge the report, assess severity, and coordinate disclosure and a fix through the private report.

EvalSeal validates supplied records and local file relationships. Reports about false or misleading evidence should identify a deterministic validation rule the gate could enforce; the gate cannot independently establish that an external report is truthful.

There aren't any published security advisories