Please do not report security vulnerabilities through public GitHub issues.
Instead, email security@watchllm.dev. We will respond within 48 hours.
The WatchLLM open-source components covered by this policy:
kernel/— Python governance kernelschemas/— JSON Schema contractsvscode/— VS Code extensionexamples/— Scenario fixtures
| Version | Supported |
|---|---|
| 0.1.x | ✅ Active |
- Reporter submits vulnerability to security@watchllm.dev
- WatchLLM team acknowledges within 48 hours
- Team investigates and develops a fix
- Fix is released and CVE is requested
- Reporter is credited (unless they opt out)