| Version | Supported |
|---|---|
| 0.1.x (latest) | ✅ |
EdgeNN is a bare-metal inference library with no network stack, but buffer overflow or integer overflow vulnerabilities in operator code could be relevant for safety-critical deployments.
To report a vulnerability:
- Do NOT open a public issue
- Email: dimitrioskafetzisd@gmail.com with subject "EdgeNN Security"
- Include: version, affected code, reproduction steps, potential impact
- Expected response time: 48 hours
Security-relevant issues include:
- Buffer overflows in operator implementations
- Integer overflow in quantization/accumulation code
- Arena allocator boundary violations
- Undefined behavior detectable by sanitizers