Report security vulnerabilities via GitHub Security Advisories — not via public issues.
Include:
- Description of the vulnerability
- Steps to reproduce
- Affected version(s)
- Potential impact
You will receive a response within 72 hours.
In scope:
- Verification gate bypass in dataset filtering — samples classified as VERIFIED that contain logical contradictions
- Dependency vulnerabilities in
satisfaction-suffices,datasets, ortorch - Issues in
VerifiedDatasetorStreamingVerifiedDatasetthat silently pass unverified samples throughstrict=Truemode
Out of scope:
- Performance / throughput issues
- Theoretical extractor coverage limitations (documented in the paper)
- Issues in the upstream SAT solver — report those to satisfaction-suffices
| Version | Supported |
|---|---|
| 0.1.x | Yes |
Confirmed vulnerabilities affecting filtering correctness will be patched and disclosed in the GitHub release notes.