Security fixes are made against the latest commit on the repository's default branch. Older commits and forks may not receive fixes.
Do not report vulnerabilities in public GitHub issues, discussions, pull requests, or commits.
Use GitHub private vulnerability reporting for this repository when it is available. If it is unavailable, contact the repository owner privately through their GitHub profile and include only the information needed to establish contact. Do not disclose exploit details publicly while a report is being assessed.
Include, where possible:
- A clear description of the issue and its impact.
- The affected version, commit, deployment configuration, or endpoint.
- Reproduction steps or a minimal proof of concept.
- Any suggested mitigation.
The maintainer will assess the report, determine whether it affects the supported version, and coordinate a fix or disclosure when appropriate. Please allow reasonable time for assessment before public disclosure.
EvalBase source code, checked-in Docker Compose configuration, and supported application dependencies are in scope. Do not test systems, accounts, datasets, or infrastructure that you do not own or lack explicit permission to test.