Skip to content

Security: SafewareTaiwan/leanai-asstf

Security

SECURITY.md

Security Policy

Supported Versions

We actively support the latest released version of leanai-asstf. Security updates are applied to the current release and may be backported to the previous minor release at our discretion.

Version Supported
1.0.x
< 1.0

Reporting a Vulnerability

If you discover a security vulnerability in ASSTF, please report it privately.

Please do not open a public issue or pull request for security vulnerabilities.

How to report

Send an email to Bentley@safeware.com.tw with the following information:

  • A description of the vulnerability
  • Steps to reproduce it
  • The affected versions
  • Any potential impact
  • Suggested mitigation or fix (if available)

What to expect

  • We will acknowledge receipt of your report within 48 hours.
  • We will investigate and provide an initial assessment within 7 days.
  • We will coordinate a fix and disclosure timeline with you.
  • We will credit you in the security advisory unless you prefer to remain anonymous.

Security Best Practices for Users

  • Keep your dependencies up to date.
  • Only load model checkpoints from trusted sources.
  • Be cautious when running adaptation on untrusted input streams.
  • Review the Community License and Commercial License before deploying ASSTF in production.

For general questions and bug reports, please use GitHub Issues.

There aren't any published security advisories