We provide security updates for the following versions of AgentIR:
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
The AgentIR project takes security seriously. If you believe you have discovered a security vulnerability, please DO NOT report it via a public GitHub issue.
Instead, please report security vulnerabilities responsibly by sending an email to:
Please include:
- Type of issue (e.g. arbitrary code execution, path traversal, secret leak, DoS).
- Step-by-step instructions or proof-of-concept to reproduce the issue.
- Affected components (e.g. safe YAML parser, adapter AST visitor, runtime harness).
- Any potential mitigations or patches you have identified.
- We will acknowledge receipt of your vulnerability report within 48 hours.
- We will provide a status update and estimated timeline for a fix within 7 business days.
- A public security advisory and patched release will be coordinated once the issue has been resolved.