Skip to content

Security: jjn1056/pagi

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in PAGI, please report it privately rather than opening a public issue.

Contact options:

  1. Email: jjnapiork@cpan.org (preferred)
  2. GitHub Security Advisories: Use the "Report a vulnerability" button in the Security tab of this repository

Please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes (optional)

Supported Versions

During the 0.x development phase, only the latest release receives security updates. Once PAGI reaches 1.0, a formal support policy will be established.

Regulatory Note

PAGI is non-commercial open source software, exempt from EU Cyber Resilience Act (CRA) requirements. Organizations integrating PAGI into commercial products are responsible for their own regulatory compliance.

There aren't any published security advisories