Skip to content

Security: cvs-health/uqlm

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest release of uqlm receives security fixes.

Version Supported
0.6.x (latest)
< 0.6.0

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

To report a vulnerability, use one of the following options:

  1. GitHub Private Vulnerability Reporting (preferred): Report a vulnerability
  2. Email: mohitsingh.chauhan@cvshealth.com

Please include as much of the following information as possible:

  • Type of issue (e.g., code injection, dependency vulnerability, data exposure)
  • Full paths of the source file(s) related to the issue
  • Location of the affected source code (tag, branch, commit, or direct URL)
  • Steps to reproduce the issue
  • Proof-of-concept or exploit code (if available)
  • Impact of the issue

We will acknowledge receipt within 72 hours and provide a more detailed response within 7 days indicating the next steps for remediation.

There aren't any published security advisories