| Version | Supported |
|---|---|
| 1.0.1 | Yes |
| Earlier versions | No |
Security fixes are prepared on dev and included in the next tagged release. Users should run the latest stable version whenever possible.
Do not open a public Issue for authentication bypasses, SSRF, data exposure, malicious file handling, dependency exploits, or leaked credentials. Use GitHub's private vulnerability reporting for this repository:
https://github.com/h46373824-tech/offerPilot-AI/security/advisories/new
Include the affected version, reproduction steps, impact, and any suggested mitigation. Do not include real resumes, access tokens, passwords, or applicant data. Maintainers should acknowledge a complete report within seven days and coordinate disclosure after a fix is available.
If an official recruitment source requests removal, changes its terms, exposes private information, or begins requiring access-control bypasses, disable that source immediately and report it through the same private channel.