Last updated: 2026-03-02
| Version | Supported |
|---|---|
| 0.1.x | Yes |
Do NOT report security vulnerabilities through public GitHub issues.
Please report vulnerabilities by emailing ziyuan.guan@ufl.edu with:
- Description of the vulnerability
- Steps to reproduce
- Affected component(s)
- Potential impact assessment
- Acknowledgment: within 48 hours
- Initial assessment: within 5 business days
- Fix or mitigation: depends on severity, targeting 30 days for critical issues
The following components are in scope for security reports:
veritas-core— runtime executorveritas-policy— policy engineveritas-audit— audit trailveritas-verify— output verificationveritas-contracts— shared types and schemas
The following are out of scope:
demo/— CLI demo runnertui/— interactive TUI demo- Documentation and whitepaper content
We follow coordinated disclosure. We will credit reporters in the advisory unless anonymity is requested.