Skip to content

Security: vitali87/code-graph-rag

.github/SECURITY.md

Security Policy

Supported Versions

Version Supported
0.0.x ✅

As the project is in early development (pre 1.0), only the latest release receives security updates. Please ensure you are running the most recent version before reporting a vulnerability.

Reporting a Vulnerability

Please do not report security vulnerabilities through public issues, pull requests, or any other public channels.

Instead, please use GitHub's private vulnerability reporting: go to the Security tab and click Report a vulnerability. This keeps the details confidential between you and the maintainers until a fix is available.

When reporting, please include:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce or a proof of concept
  • The version(s) affected
  • Any suggested fix, if available

What to Expect

  • Acknowledgement within 72 hours of your report
  • Status update within 7 days with an initial assessment
  • Resolution target of 30 days for confirmed vulnerabilities, though critical issues will be prioritized for faster turnaround

If the vulnerability is accepted, we will work on a fix, coordinate disclosure with you, and credit you in the release notes (unless you prefer to remain anonymous).

If the vulnerability is declined, we will provide a clear explanation of why.

Incident Response

The public incident response plan describes how the maintainer investigates, contains and recovers from security incidents, including compromised releases, and communicates actions users should take. Reporting instructions, supported versions and response targets remain in this policy.

Scope

This policy applies to the code-graph-rag Python package and its official repository. Third party dependencies are outside the direct scope of this policy, though we use Dependabot to monitor and update them.

Security Measures in This Project

  • Dependency scanning: Dependabot alerts and security updates are enabled, with version updates configured weekly for GitHub Actions, Docker and pip
  • Secret scanning: GitHub secret scanning is active on this repository
  • Push protection: Secret scanning push protection blocks commits containing supported secrets before they reach the repository
  • Code scanning: CodeQL default setup analyses the Actions, C/C++, C#, JavaScript/TypeScript and Python code in this repository on every pull request targeting main, on every push to main and weekly, and reports findings to the Security tab. The main ruleset requires CodeQL results on every pull request and blocks the merge while CodeQL reports any new alert on it
  • Static analysis gate: The SonarCloud workflow analyses pushes to main and pull requests targeting main from a branch of this repository, Dependabot's excepted, and on those pull requests the All Checks Pass status check fails while SonarCloud reports any open issue, vulnerabilities included
  • Python security linting: Bandit runs as a pre-commit hook, and the Lint & Format CI job runs the same hook on every pull request, so a high-severity finding fails All Checks Pass. The same job's ruff check enforces Ruff's flake8-bandit (S) rules outside tests, and pyproject.toml records why each rule left off is off
  • Fuzzing: ClusterFuzzLite runs the harnesses in fuzz/ against every pull request targeting main, and daily for longer against main
  • Vulnerability scanning: The OSV-Scanner workflow checks dependencies against the OSV database on pull requests targeting main, on pushes to main and weekly, and reports findings to the Security tab
  • Supply chain scorecard: The OpenSSF Scorecard workflow audits the repository's supply chain posture and reports findings to the Security tab
  • Private vulnerability reporting: Enabled, so vulnerabilities can be reported privately through the Security tab as described above
  • Branch protection: The main branch is covered by a ruleset that requires changes to arrive by pull request with the All Checks Pass status check green and CodeQL results carrying no new alert, and blocks branch deletion and force pushes

Preferred Languages

We accept security reports in English.

Learn more about advisories related to vitali87/code-graph-rag in the GitHub Advisory Database