| Version | Supported |
|---|---|
| 0.1.x | ✅ |
As Kitaru is in early development, only the latest release receives security updates. We recommend always running the most recent version.
If you discover a security vulnerability in Kitaru, please report it responsibly by emailing security@zenml.io. Do not open a public GitHub issue for security vulnerabilities.
When reporting, please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce or a proof of concept
- The version(s) of Kitaru affected
- Acknowledgement within 2 business days confirming we received your report.
- Status updates at least every 7 days until the issue is resolved.
- If the vulnerability is accepted, we will work on a fix and coordinate disclosure with you. We aim to release a patch promptly and will credit reporters unless they prefer to remain anonymous.
- If the vulnerability is declined (e.g. out of scope or not reproducible), we will explain our reasoning.
We appreciate your help in keeping Kitaru and its users safe.