Please report security issues privately instead of opening a public issue.
Contact: fangw717161@gmail.com
Include:
- Software version / image digest / binary SHA-256
- Deployment profile (container memory/CPU limits, configuration)
- Steps to reproduce, expected vs actual behavior
- We will acknowledge within 3 business days.
- We aim to ship a fixed release with updated evidence within a reasonable window depending on severity.
- Security fixes are documented in the release notes and in the release evidence bundle.
- Run the container with
--read-onlyand a bounded--tmpfs /tmp. - Always set explicit
--memory/--memory-swap/--cpus/--pids-limit. - Do not use
--oom-kill-disable; a controlled admission rejection is the designed failure mode. - Keep the model artifact layer digest-constrained (see release evidence).