If you discover a security issue in TokenDamper, report it privately to the project maintainers instead of opening a public issue.
Include as much detail as possible, including:
- affected version
- description of the issue
- reproduction steps
- expected impact
- any relevant logs or fixtures
Security support applies to released, maintained versions of TokenDamper.
This repository is currently in the pre-release stage, so there are no stable security-supported versions yet.
TokenDamper is designed to optimize context safely and predictably.
Security principles:
- prefer deterministic behavior
- avoid hidden network dependencies in the core path
- keep fallback explicit
- minimize the trust surface
- keep benchmark and runtime paths separated
Please allow time for the maintainers to investigate and respond before public disclosure.
The preferred process is:
- Report privately
- Wait for acknowledgment
- Collaborate on a fix
- Disclose publicly once a fix is available or a disclosure timeline is agreed