| Version | Supported |
|---|---|
| main | ✅ |
If you discover a security vulnerability, please report it responsibly:
- Do not open a public issue.
- Email the maintainers or use GitHub's private vulnerability reporting feature on the Security tab.
- Include a description of the vulnerability, steps to reproduce, and any potential impact.
We will acknowledge receipt within 48 hours and aim to provide a fix or mitigation within 7 days for critical issues.
This policy covers the GlowBack engine (crates/), Python bindings, FastAPI
gateway, and Streamlit UI. Third-party dependencies are monitored via Dependabot.