mushin is under active development. Security fixes are applied to the latest
released version and main. Please make sure you are on the latest version
before reporting.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, use GitHub's private vulnerability reporting for this repository:
- Go to the Security tab of the repository.
- Click "Report a vulnerability".
- Fill out the form with as much detail as you can.
This delivers the report privately to the maintainers. You should receive an acknowledgement within a few days. If the issue is confirmed, we will work on a fix and coordinate a disclosure timeline with you.
- A description of the vulnerability and its impact
- Steps to reproduce (a minimal proof of concept is ideal)
- Affected version(s) and environment (Python / torch / OS)
- Any suggested remediation, if you have one
We appreciate responsible disclosure and will credit reporters who wish to be acknowledged once a fix is released.