We take security seriously and actively maintain security updates for the following versions of our framework components:
| Version | Supported | Security Updates | Bug Fixes |
|---|---|---|---|
| 1.2.x | ✅ | ✅ | ✅ |
| 1.1.x | ✅ | ✅ | ✅ |
| 1.0.x | ❌ | ❌ | ✅ |
| < 1.0 | ❌ | ❌ | ❌ |
- MODEL_for_framework: Core framework (ACTIVE status) - Full security support
- MODEL_for_STKHLD_AI_COLLAB: Stakeholder collaboration model (DRAFT status) - Limited support
We appreciate your help in keeping our AI frameworks and methodologies secure. If you discover a security vulnerability, please follow these steps:
-
Email: Send security reports to ( peter stone mail de )
- Use the subject line:
[SECURITY] Vulnerability Report - [Component Name] - Include detailed steps to reproduce the issue
- Provide your contact information for follow-up
- Use the subject line:
-
GitHub Security Advisories: For public repositories, you can also use GitHub Security Advisories
Please provide as much detail as possible:
- Description: Clear description of the vulnerability
- Impact: Potential impact on users, data, or systems
- Steps to Reproduce: Detailed reproduction steps
- Affected Components: Which parts of the framework are affected
- Environment: Your setup (OS, Python version, etc.)
- Proof of Concept: If available, include PoC code or screenshots
- Initial Response: Within 48 hours of receiving your report
- Vulnerability Assessment: Within 7 days
- Fix Development: Within 30 days for critical vulnerabilities
- Public Disclosure: Coordinated disclosure after fix is deployed
We classify vulnerabilities using the following severity levels:
- Critical: Immediate threat to user data or system integrity
- High: Significant security risk with potential for exploitation
- Medium: Security weakness with limited exploitation potential
- Low: Minor security improvements needed
We recognize and appreciate security researchers who help improve our frameworks. With your permission, we'll acknowledge your contribution in our security acknowledgments.
We consider security research conducted in accordance with this policy to be authorized. We will not initiate legal action against researchers who follow these guidelines.
- Security Team: see above
- General Support: see above
- Repository: https://github.com/peterstone649/md
Thank you for helping keep our AI frameworks secure!