The InferenceOS maintainers take security seriously. We appreciate your efforts to responsibly disclose security vulnerabilities.
Security updates are actively applied to the following versions of InferenceOS:
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
Please do NOT report security vulnerabilities through public GitHub issues.
Instead, please report vulnerabilities directly to the InferenceOS Maintainers by emailing:
- A clear description of the vulnerability and its potential impact.
- Step-by-step instructions or proof-of-concept script to reproduce the vulnerability.
- Affected components (e.g., HTTP server authentication, API endpoint parser, C++ ctypes bindings).
- System environment details (OS, Python version, hardware profile).
- Acknowledgment: We will acknowledge receipt of your vulnerability report within 48 hours.
- Investigation: Maintainers will investigate the vulnerability and assess its severity.
- Fix & Patch Release: We will work on a patch and notify you when a fix is ready for testing.
- Public Advisory: Once patched, a public security advisory will be published acknowledging your contribution (unless you request to remain anonymous).
Thank you for helping keep InferenceOS secure!