| Version | Supported |
|---|---|
| 0.1.x | Yes |
Do not file security issues as public GitHub issues.
Instead, email security@testmuai.com with:
- Description of the vulnerability
- Steps to reproduce
- Impact assessment (if known)
- Your contact information
This policy covers:
- The
evidence-clilibrary and its CLI (validate,finalize) - Reading and sealing
.evidencepacks — path containment, zip handling, and ranged reads over remote blobs - The JSON Schemas and the validation logic
Thank you for helping keep evidence-cli safe.