Security Policy¶
Supported Versions¶
ClaimBound Evidence is currently pre-1.0 public research tooling. Security fixes are applied to the default branch and to the latest tagged release when practical.
| Version | Supported |
|---|---|
Latest main |
Yes |
| Latest tagged release | Yes |
| Older releases | No, unless a severe issue affects public users |
Scope and duration of support¶
- Scope: security fixes are made on
mainand released as the next tagged release. - Duration: a tagged release is supported until the next tagged release is published. The project is pre-1.0 and has no long-term-support branch.
- End of security updates: once a newer release exists, older releases receive no further security updates. A severe issue that affects public users of an older release may be backported at the maintainer's discretion; the advisory then names the fixed versions. Users of older releases should upgrade to the latest release.
Published vulnerability data¶
Confirmed vulnerabilities are published, after a fix is available, as GitHub Security
Advisories (with a CVE identifier when one is assigned) at
https://github.com/ClaimBound/claimbound-evidence/security/advisories. Each advisory
states the affected and fixed versions, and the fix is also listed in the release notes
and CHANGELOG.md. No vulnerabilities have been confirmed so far.
Reporting a Vulnerability¶
Please report suspected vulnerabilities privately through GitHub Security Advisories:
https://github.com/ClaimBound/claimbound-evidence/security/advisories/new
Do not open a public issue for vulnerabilities involving:
- dependency compromise;
- CI or GitHub Actions permissions;
- repository publication guard bypasses;
- accidental exposure of raw payloads, local paths, credentials, tokens, or private-source material;
- unsafe handling of operator-supplied files.
Expected Response¶
I aim to acknowledge valid reports within 7 calendar days. If the report is accepted, I will try to provide a fix, mitigation, or documented decision within 30 calendar days, depending on severity and available maintainer time.
If the report is declined, I will explain the reason where possible.
Project-Specific Boundaries¶
This repository is public ClaimBound evidence foreground. It must not contain raw external payloads, credentials, private local paths, private-source code, or private production integrations.
Security reports about private systems, private-source implementations, or unrelated infrastructure are out of scope for this public repository unless they demonstrate a direct leak or vulnerability in the public evidence code.
Safe Handling Notes¶
When reproducing evidence runs:
- keep raw payloads outside the repository;
- publish hashes, manifests, summaries, and claim boundaries only;
- do not include access tokens, cookies, API keys, or private local paths in reports;
- verify generated artifacts before committing.
Provenance And Audit-Log Handling¶
AI provenance bundles, GitHub organization audit-log exports, AI session logs and private reviewer materials may contain account metadata, private messages, local paths or sensitive operational details. Do not commit those raw exports to this public repository.
Use public PRs, commits, releases, GitHub Actions runs, evidence cards and the registry as the public provenance trail. Store any raw audit-log export only in a private AI provenance archive, redact before sharing externally and publish hashes or public URLs instead of private logs where possible.
If an audit-log export, AI transcript, raw payload, token, private path or private-source detail is accidentally committed or disclosed, report it through GitHub Security Advisories:
https://github.com/ClaimBound/claimbound-evidence/security/advisories/new
Supply Chain¶
- Releases are built and published by GitHub Actions to PyPI through Trusted Publishing (OpenID Connect); no long-lived PyPI API token is stored in the repository.
- Dependabot proposes dependency and GitHub Actions updates weekly.
- OpenSSF Scorecard
results for this repository are published by the
scorecardworkflow.