Skip to content

Security: rudy-07/InferenceOS

Security

SECURITY.md

Security Policy

The InferenceOS maintainers take security seriously. We appreciate your efforts to responsibly disclose security vulnerabilities.


Supported Versions

Security updates are actively applied to the following versions of InferenceOS:

Version Supported
1.0.x
< 1.0

Reporting a Vulnerability

Please do NOT report security vulnerabilities through public GitHub issues.

Instead, please report vulnerabilities directly to the InferenceOS Maintainers by emailing:

📧 security@inferenceos.org

What to Include in Your Report

  • A clear description of the vulnerability and its potential impact.
  • Step-by-step instructions or proof-of-concept script to reproduce the vulnerability.
  • Affected components (e.g., HTTP server authentication, API endpoint parser, C++ ctypes bindings).
  • System environment details (OS, Python version, hardware profile).

Our Response Process

  1. Acknowledgment: We will acknowledge receipt of your vulnerability report within 48 hours.
  2. Investigation: Maintainers will investigate the vulnerability and assess its severity.
  3. Fix & Patch Release: We will work on a patch and notify you when a fix is ready for testing.
  4. Public Advisory: Once patched, a public security advisory will be published acknowledging your contribution (unless you request to remain anonymous).

Thank you for helping keep InferenceOS secure!

There aren't any published security advisories