Skip to content

Security: mantraraval/JobSense

Security

SECURITY.md

Security Policy

We take the security of JobSense and its associated models, dataset, and demo spaces seriously. If you believe you have found a security vulnerability, we appreciate your help in disclosing it to us in a responsible manner.

Supported Versions

Only the latest release of JobSense is actively supported for security patches.

Version Supported Notes
v1.0.x ✅ Yes Active release
< v1.0 ❌ No Development / pre-releases

Reporting a Vulnerability

Please do not open a public issue for security-related items.

Instead, report security vulnerabilities by reaching out directly to the maintainer:

  • Contact Email/GitHub: Please contact Mantra Raval via GitHub at https://github.com/mantraraval.
  • Scope: This policy covers the JobSense repository, fine-tuning scripts, weight-merging scripts, local deployment wrappers, and the Hugging Face Space demo.

What to Include

When reporting a vulnerability, please include the following details:

  1. A descriptive title and detailed summary of the vulnerability.
  2. Step-by-step instructions (or a Proof of Concept script) to reproduce the issue.
  3. The potential impact of the vulnerability (e.g., prompt injection, remote code execution in demo space, deserialization vulnerabilities, etc.).
  4. The environment where the vulnerability was observed (OS, library versions, hardware context).

Response Process

After receiving your report, the maintainer will:

  1. Acknowledge the receipt of your report within 48 hours.
  2. Work to verify and reproduce the vulnerability.
  3. Draft a patch or mitigation strategy.
  4. Coordinate a release date for the security update.
  5. Provide credit to the reporter (if desired) in the release notes.

We ask that you do not disclose the vulnerability publicly until a fix has been released or we have agreed on a coordinated disclosure timeline.

There aren't any published security advisories