Skip to content

Security: javierdejesusda/checkllm

Security

SECURITY.md

Security Policy

Supported Versions

Version Support
5.x Active support
4.x Security fixes only
< 4.0 End of life

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Preferred: GitHub Private Security Advisory

  1. Go to: https://github.com/javierdejesusda/checkllm/security/advisories/new
  2. Fill in the vulnerability details (description, reproduction steps, impact).
  3. Submit — this creates a private draft visible only to maintainers.

Alternative: Email

Send details to javier.dejesusj9@gmail.com with the subject line [SECURITY] checkllm vulnerability report.

Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Affected version(s)
  • Potential impact assessment
  • Suggested fix (optional)

Response Timeline

Stage Target
Acknowledgement 48 hours
Initial assessment 5 business days
Fix timeline communicated 10 business days
Patch released 90 days or less

Published Advisories

https://github.com/javierdejesusda/checkllm/security/advisories

Out of Scope

  • Social engineering attacks
  • Security issues in third-party judge backends (OpenAI, Anthropic, Gemini, etc.)
  • API key exposure caused by end-user misconfiguration
  • Vulnerabilities in Python itself or its standard library
  • Issues requiring physical access to the user's machine

There aren't any published security advisories