This project is under active development. Security fixes are applied to the
main branch and included in the latest tagged release.
| Version | Supported |
|---|---|
| latest | ✅ |
| < latest | ❌ |
If you discover a security vulnerability, please do not open a public GitHub issue. Instead, report it privately using one of the following channels:
- GitHub: open a private security advisory for this repository (preferred).
- Email the maintainers with a description of the issue, steps to reproduce, and any relevant logs or proof-of-concept code.
We will acknowledge your report within 5 business days and aim to provide a fix or mitigation plan within 30 days, depending on severity.
Areas of particular interest for security review:
- The FastAPI inference service (
serving/) — input validation, request size limits, inference timeout, model/adapter path handling. - Dependency supply chain (
requirements.txt,pyproject.toml). - Docker images and CI/CD workflows (
Dockerfile.serveruns as non-rootappuser). - Handling of model artifacts and configuration files (no secrets should be
committed or baked into images). Use
.env.exampleas a template — never commit a.envfile with real credentials.
| Control | Implementation |
|---|---|
| Non-root container | appuser in Dockerfile.serve |
| Input size cap | EXTRACT_MAX_REQUEST_CHARS (default 8 000 chars) |
| Inference timeout | EXTRACT_INFERENCE_TIMEOUT_SECONDS (default 120 s) |
| Concurrency cap | EXTRACT_MAX_CONCURRENCY semaphore |
| No arbitrary code | trust_remote_code=False in all model loading paths |
| Config validation | Only known dataclass fields accepted from YAML overrides |
| Optional API key auth | EXTRACT_API_KEY gates /v1/extract and /metrics via a Bearer token, compared with hmac.compare_digest (constant-time) |
| Build context hygiene | .dockerignore excludes .env, .git/, and pickle-based checkpoint files from image builds |
| Dependency scanning | Trivy filesystem scan runs in CI (report-only) |
If EXTRACT_API_KEY is left unset (the default), the API runs without
authentication — suitable only for private/internal deployments, or when placed
behind a reverse proxy (nginx, Caddy) or API gateway that handles auth (API keys,
mTLS) itself. For any internet-facing deployment, set EXTRACT_API_KEY and add a
per-IP rate limiter (e.g. slowapi) in front of the concurrency semaphore, which
only bounds simultaneous requests, not request rate.
We follow coordinated disclosure: once a fix is available, we will publish a security advisory crediting the reporter (unless anonymity is requested).