Security fixes are applied to the latest tagged release and the main branch.
Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting feature for this repository. Include the affected revision, impact, reproduction steps, and any suggested mitigation.
Avoid attaching model weights, access tokens, private infrastructure addresses, customer prompts, or proprietary routing traces. Use synthetic fixtures wherever possible.
Relevant reports include unsafe checkpoint parsing, out-of-bounds kernel access, malformed routing metadata, transport authentication/integrity failures, denial-of-service conditions, and accidental secret or model-artifact exposure.