Skip to content

Security Policy

Supported Versions

ClaimBound Evidence is currently pre-1.0 public research tooling. Security fixes are applied to the default branch and to the latest tagged release when practical.

Version Supported
Latest main Yes
Latest tagged release Yes
Older releases No, unless a severe issue affects public users

Scope and duration of support

  • Scope: security fixes are made on main and released as the next tagged release.
  • Duration: a tagged release is supported until the next tagged release is published. The project is pre-1.0 and has no long-term-support branch.
  • End of security updates: once a newer release exists, older releases receive no further security updates. A severe issue that affects public users of an older release may be backported at the maintainer's discretion; the advisory then names the fixed versions. Users of older releases should upgrade to the latest release.

Published vulnerability data

Confirmed vulnerabilities are published, after a fix is available, as GitHub Security Advisories (with a CVE identifier when one is assigned) at https://github.com/ClaimBound/claimbound-evidence/security/advisories. Each advisory states the affected and fixed versions, and the fix is also listed in the release notes and CHANGELOG.md. No vulnerabilities have been confirmed so far.

Reporting a Vulnerability

Please report suspected vulnerabilities privately through GitHub Security Advisories:

https://github.com/ClaimBound/claimbound-evidence/security/advisories/new

Do not open a public issue for vulnerabilities involving:

  • dependency compromise;
  • CI or GitHub Actions permissions;
  • repository publication guard bypasses;
  • accidental exposure of raw payloads, local paths, credentials, tokens, or private-source material;
  • unsafe handling of operator-supplied files.

Expected Response

I aim to acknowledge valid reports within 7 calendar days. If the report is accepted, I will try to provide a fix, mitigation, or documented decision within 30 calendar days, depending on severity and available maintainer time.

If the report is declined, I will explain the reason where possible.

Project-Specific Boundaries

This repository is public ClaimBound evidence foreground. It must not contain raw external payloads, credentials, private local paths, private-source code, or private production integrations.

Security reports about private systems, private-source implementations, or unrelated infrastructure are out of scope for this public repository unless they demonstrate a direct leak or vulnerability in the public evidence code.

Safe Handling Notes

When reproducing evidence runs:

  • keep raw payloads outside the repository;
  • publish hashes, manifests, summaries, and claim boundaries only;
  • do not include access tokens, cookies, API keys, or private local paths in reports;
  • verify generated artifacts before committing.

Provenance And Audit-Log Handling

AI provenance bundles, GitHub organization audit-log exports, AI session logs and private reviewer materials may contain account metadata, private messages, local paths or sensitive operational details. Do not commit those raw exports to this public repository.

Use public PRs, commits, releases, GitHub Actions runs, evidence cards and the registry as the public provenance trail. Store any raw audit-log export only in a private AI provenance archive, redact before sharing externally and publish hashes or public URLs instead of private logs where possible.

If an audit-log export, AI transcript, raw payload, token, private path or private-source detail is accidentally committed or disclosed, report it through GitHub Security Advisories:

https://github.com/ClaimBound/claimbound-evidence/security/advisories/new

Supply Chain

  • Releases are built and published by GitHub Actions to PyPI through Trusted Publishing (OpenID Connect); no long-lived PyPI API token is stored in the repository.
  • Dependabot proposes dependency and GitHub Actions updates weekly.
  • OpenSSF Scorecard results for this repository are published by the scorecard workflow.