Files

1.6 KiB

Security policy

Supported version

Security fixes are made for the latest released minor version. At the time of publication that is ModelForge 1.2.x. Upgrade to the latest patch before reporting a problem that may already be fixed.

Reporting a vulnerability

Do not open a public issue for a suspected vulnerability, leaked credential, private topology or exploit. Send the report privately to security@itworx.tech with:

  • the affected version or commit;
  • the component and reachable entry point;
  • reproduction steps or a minimal proof of concept;
  • the impact and any prerequisites you observed;
  • whether you believe active exploitation or credential exposure occurred.

Do not access data that is not yours, degrade a running service, persist access, or publish the details before a fix is available. We will acknowledge a usable report, coordinate validation and credit, and publish an advisory when users have a remediation.

The repository owner must confirm that security@itworx.tech is a monitored mailbox before the public repository is enabled. Until then, contact the owner privately through the repository host.

Security model

Model artifacts are untrusted input. ModelForge resolves immutable upstream revisions, keeps downloads in quarantine, verifies their size and digest, performs static inspection, disables remote code, and requires evidence plus human approval before production promotion. See docs/security/THREAT_MODEL.md and docs/security/MODEL_SUPPLY_CHAIN_POLICY.md.