Skip to content

Security: neuml/annotateai

Security

SECURITY.md

Security Policy

Report a Vulnerability

If you believe you found a security vulnerability with NeuML projects, please send a message to [email protected].

In your message, please include:

  1. Reproducible steps to trigger the vulnerability.
  2. An explanation of what makes you think there is a direct vulnerability specifically with the project.
  3. Confirm this is indeed relevant to the specific project and not an upstream library/framework vulnerability.
  4. Any additional relevant information you may have.

Vulnerability Response

We'll review your report promptly and perform an analysis to confirm that it's indeed a vulnerability.

We won't disclose any information you share with us but we'll use it to get the issue fixed.

If we feel this vulnerability is really a vulnerability in an upstream library/framework dependency, we'll decline this report and direct you to the relevant project.

Our goal is to disclose relevant bugs as soon as possible once a user mitigation is available.

There aren’t any published security advisories