Skip to content

Latest commit

 

History

History
30 lines (19 loc) · 1018 Bytes

File metadata and controls

30 lines (19 loc) · 1018 Bytes

Security Policy

Supported Scope

This repository accepts security reports for:

  1. Python package runtime and verification CLI (src/zpe_taste/).
  2. Packaging and release metadata (pyproject.toml, CITATION.cff, REPRODUCIBILITY.md, .zenodo.json).
  3. CI and release pipeline configuration.

Scientific disagreements about the repository's negative finding are not security issues. Route those through the public issue tracker using the evidence-dispute path.

Reporting

Please report vulnerabilities privately to architects@zer0pa.ai with:

  1. A clear impact summary.
  2. Reproduction steps or proof-of-concept.
  3. Affected versions or commit ranges.
  4. Suggested remediation when available.

Do not open a public issue for a security vulnerability.

Response Targets

  1. Initial acknowledgement: within 5 business days.
  2. Triage and severity classification: within 10 business days.
  3. Remediation timeline: shared post-triage.

Public disclosure should be coordinated after a fix is available.