Skip to content

Latest commit

 

History

History
49 lines (34 loc) · 1.75 KB

File metadata and controls

49 lines (34 loc) · 1.75 KB

Security Policy

We take the security of Samyama Graph seriously. Thank you for helping keep the project and its users safe.

Supported versions

Version Supported
1.1.x ✅ Yes
< 1.1 ❌ No (please upgrade)

Security fixes land on the latest 1.1.x line. We recommend always running the most recent release.

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.

Instead, use either of these private channels:

  1. GitHub private vulnerability reporting (preferred) — go to the repository's Security tab → Report a vulnerability. This opens a private advisory visible only to the maintainers.
  2. Emailenquiry@samyama.ai with the subject line starting SECURITY:.

Please include as much of the following as you can:

  • A description of the vulnerability and its impact.
  • Steps to reproduce (a minimal proof-of-concept helps a lot).
  • Affected version(s) or commit SHA.
  • Any suggested mitigation, if you have one.

What to expect

  • Acknowledgement of your report within 3 business days.
  • An initial assessment and severity triage within 7 business days.
  • Regular updates as we work on a fix, and credit in the release notes / advisory once the issue is resolved (unless you prefer to remain anonymous).

Coordinated disclosure

We follow a coordinated-disclosure model. Please give us reasonable time to investigate and release a fix before any public disclosure. We're happy to coordinate timing with you and to acknowledge your contribution.

Thank you for acting responsibly and helping protect the Samyama Graph community.