Skip to content

Security: KRLabsOrg/.github

Security

SECURITY.md

Security policy

This policy covers every public KR Labs repository, including LettuceDetect, VerbatimRAG, RuleChef, and their clients and integrations.

Reporting a vulnerability

Please report security issues privately through GitHub:

  1. Open the affected repository.
  2. Go to the Security tab and choose Report a vulnerability.
  3. Describe the issue, the affected version or commit, and the steps to reproduce it.

Do not open a public issue, pull request, or discussion for a security problem. If you are unsure whether something is a security issue, report it privately anyway.

What to expect

  • We acknowledge a report within 5 working days.
  • We confirm or rule out the issue and tell you what we plan to do.
  • We fix confirmed issues in the latest release and publish a GitHub security advisory. We credit you in it unless you ask us not to.

Supported versions

Security fixes go into the latest release of each package on PyPI. Older releases are not patched; please upgrade.

Scope

In scope: code in our public repositories and the packages we publish from them.

Out of scope:

  • Vulnerabilities in third-party dependencies with no exploitable path through our code. Please report those upstream.
  • Model output quality, such as missed or false hallucination detections. Those are regular bug reports and belong in public issues.
  • Findings from automated scanners without a demonstrated impact.

There aren't any published security advisories