Skip to content

Security: samyama-ai/samyama-graph

Security

SECURITY.md

Security Policy

We take the security of Samyama Graph seriously. Thank you for helping keep the project and its users safe.

Supported versions

Version Supported
1.1.x ✅ Yes
< 1.1 ❌ No (please upgrade)

Security fixes land on the latest 1.1.x line. We recommend always running the most recent release.

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.

Instead, use either of these private channels:

  1. GitHub private vulnerability reporting (preferred) — go to the repository's Security tab → Report a vulnerability. This opens a private advisory visible only to the maintainers.
  2. Emailenquiry@samyama.ai with the subject line starting SECURITY:.

Please include as much of the following as you can:

  • A description of the vulnerability and its impact.
  • Steps to reproduce (a minimal proof-of-concept helps a lot).
  • Affected version(s) or commit SHA.
  • Any suggested mitigation, if you have one.

What to expect

  • Acknowledgement of your report within 3 business days.
  • An initial assessment and severity triage within 7 business days.
  • Regular updates as we work on a fix, and credit in the release notes / advisory once the issue is resolved (unless you prefer to remain anonymous).

Coordinated disclosure

We follow a coordinated-disclosure model. Please give us reasonable time to investigate and release a fix before any public disclosure. We're happy to coordinate timing with you and to acknowledge your contribution.

Thank you for acting responsibly and helping protect the Samyama Graph community.

There aren't any published security advisories