CxLLM-SDK/SECURITY.md
cx-git-agent d5d36a1db4
Some checks failed
ci / build (${{ matrix.os }}) (macos-14) (push) Has been cancelled
chore: snapshot local working tree (2026-05-17T20:24:08Z)
2026-05-17 15:27:25 -05:00

576 B

Security policy for CxLLM-SDK

Reporting a vulnerability

Please email security@cxllm-studio.com with:

  • A description of the vulnerability and its impact.
  • Steps to reproduce, ideally with a minimal proof-of-concept.
  • The affected version(s) / commit SHAs.

We aim to acknowledge within 2 business days and to publish a fix or mitigation within 30 days for high-severity issues.

Do not open a public Gitea / GitHub issue for vulnerabilities.

Supported versions

Only the main branch and the most recent tagged release receive security updates.