We actively support the latest released version of leanai-asstf. Security updates are applied to the current release and may be backported to the previous minor release at our discretion.
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
If you discover a security vulnerability in ASSTF, please report it privately.
Please do not open a public issue or pull request for security vulnerabilities.
Send an email to Bentley@safeware.com.tw with the following information:
- A description of the vulnerability
- Steps to reproduce it
- The affected versions
- Any potential impact
- Suggested mitigation or fix (if available)
- We will acknowledge receipt of your report within 48 hours.
- We will investigate and provide an initial assessment within 7 days.
- We will coordinate a fix and disclosure timeline with you.
- We will credit you in the security advisory unless you prefer to remain anonymous.
- Keep your dependencies up to date.
- Only load model checkpoints from trusted sources.
- Be cautious when running adaptation on untrusted input streams.
- Review the Community License and Commercial License before deploying ASSTF in production.
For general questions and bug reports, please use GitHub Issues.