Skip to content

Security: WatchLLM/watchllm-oss

Security

.github/SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, email security@watchllm.dev. We will respond within 48 hours.

Scope

The WatchLLM open-source components covered by this policy:

  • kernel/ — Python governance kernel
  • schemas/ — JSON Schema contracts
  • vscode/ — VS Code extension
  • examples/ — Scenario fixtures

Supported Versions

Version Supported
0.1.x ✅ Active

Disclosure Process

  1. Reporter submits vulnerability to security@watchllm.dev
  2. WatchLLM team acknowledges within 48 hours
  3. Team investigates and develops a fix
  4. Fix is released and CVE is requested
  5. Reporter is credited (unless they opt out)

There aren't any published security advisories