Skip to content

Security: asguinea/conformal-pathways

SECURITY.md

Security

Only the current main branch and latest 0.4.x release receive fixes. This is experimental research software, not a clinical system or a sandbox for untrusted code. Historical benchmark tags are immutable reproduction snapshots; use an isolated environment for them and review the recorded dependencies.

Report vulnerabilities through GitHub private vulnerability reporting. Include a minimal generated-data example, affected revision, impact, and reproduction steps. Do not post exploit details, credentials, or participant data in a public issue. No response-time guarantee is offered.

Treat supplied configurations, model files, NumPy artifacts, archives, and Python extensions as trusted local inputs. Do not load artifacts from an untrusted source. Run experiments without credentials and with only the required dataset access. Real traces and caches can contain sensitive or restricted material; keep them outside tracked files. The demo needs no external data or credentials.

There aren't any published security advisories