The latest published preview or stable release receives security fixes.
Please do not disclose a suspected vulnerability in a public issue before a fix is available. Use the repository's private GitHub Security Advisory reporting flow. If that form is unavailable, contact Sultan Alfaifi through:
Include the affected version, reproduction steps, expected impact, and any suggested mitigation. Do not include secrets or personal data.
- Hardware inspection remains local.
- Network requests are limited to allowlisted HTTPS sources.
- Model installation is approval-gated.
- Install commands are executed as argument arrays without shell interpolation.
- Unknown model layouts are not guessed or automatically trusted.