Skip to content

Security: Mesutcydev/ios-local-llm

SECURITY.md

Security policy

Supported versions

Security fixes are made on the current main branch. There are no supported pre-built releases at this time.

Reporting a vulnerability

Do not open a public issue for a vulnerability that could put users or their data at risk.

Use GitHub's private vulnerability reporting feature on this repository. If that is unavailable, email mesutcy@gmail.com with:

  • a concise description and impact;
  • affected files or features;
  • reproduction steps or a proof of concept;
  • any suggested mitigation; and
  • whether you want public credit.

Do not include real user data or active credentials. You should receive an acknowledgement within seven days. Please allow reasonable time for a fix before public disclosure.

Reports are handled on a best-effort basis by a volunteer maintainer. No bug bounty is currently offered.

Scope

Useful reports include local API or bridge authentication bypasses, unsafe URL or file handling, secret exposure, sandbox escapes, and privacy claims that do not match actual network behavior.

Reports about third-party models or dependencies should also be sent to the upstream maintainer when appropriate.

There aren't any published security advisories