Report vulnerabilities to security@cocoindex.io — please do not open public issues. Include a description, reproduction steps, and any relevant logs or proof-of-concept.
Process, response SLAs, and disclosure terms are defined in the CocoIndex organization security policy.
Scope: the CocoIndex open-source framework — this repository and the
PyPI package cocoindex. Security fixes land in the latest release.