Security fixes target the latest published light-ocr release. If a report affects an older version, maintainers may ask you to confirm it against the latest release.
Use GitHub private vulnerability reporting. Please do not open a public issue for an undisclosed vulnerability.
Include, when available:
- The affected light-ocr version, API, operating system, and architecture.
- A clear description of the impact and the conditions required to reproduce it.
- A minimal reproduction or diagnostic output with secrets and private OCR inputs removed.
- Any suggested mitigation or fix.
Maintainers will review the report privately and coordinate remediation and disclosure with the reporter.