| Version | Supported |
|---|---|
| 0.0.x | ✅ |
As the project is in early development (pre 1.0), only the latest release receives security updates. Please ensure you are running the most recent version before reporting a vulnerability.
Please do not report security vulnerabilities through public issues, pull requests, or any other public channels.
Instead, please use GitHub's private vulnerability reporting: go to the Security tab and click Report a vulnerability. This keeps the details confidential between you and the maintainers until a fix is available.
When reporting, please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce or a proof of concept
- The version(s) affected
- Any suggested fix, if available
- Acknowledgement within 72 hours of your report
- Status update within 7 days with an initial assessment
- Resolution target of 30 days for confirmed vulnerabilities, though critical issues will be prioritized for faster turnaround
If the vulnerability is accepted, we will work on a fix, coordinate disclosure with you, and credit you in the release notes (unless you prefer to remain anonymous).
If the vulnerability is declined, we will provide a clear explanation of why.
The public incident response plan describes how the maintainer investigates, contains and recovers from security incidents, including compromised releases, and communicates actions users should take. Reporting instructions, supported versions and response targets remain in this policy.
This policy applies to the code-graph-rag Python package and its official repository. Third party dependencies are outside the direct scope of this policy, though we use Dependabot to monitor and update them.
- Dependency scanning: Dependabot alerts and security updates are enabled, with version updates configured weekly for GitHub Actions, Docker and pip
- Secret scanning: GitHub secret scanning is active on this repository
- Push protection: Secret scanning push protection blocks commits containing supported secrets before they reach the repository
- Code scanning: CodeQL default setup analyses the Actions, C/C++, C#, JavaScript/TypeScript and Python code in this repository on every pull request targeting
main, on every push tomainand weekly, and reports findings to the Security tab. Themainruleset requires CodeQL results on every pull request and blocks the merge while CodeQL reports any new alert on it - Static analysis gate: The SonarCloud workflow analyses pushes to
mainand pull requests targetingmainfrom a branch of this repository, Dependabot's excepted, and on those pull requests theAll Checks Passstatus check fails while SonarCloud reports any open issue, vulnerabilities included - Python security linting: Bandit runs as a pre-commit hook, and the
Lint & FormatCI job runs the same hook on every pull request, so a high-severity finding failsAll Checks Pass. The same job'sruff checkenforces Ruff's flake8-bandit (S) rules outside tests, andpyproject.tomlrecords why each rule left off is off - Fuzzing: ClusterFuzzLite runs the harnesses in
fuzz/against every pull request targetingmain, and daily for longer againstmain - Vulnerability scanning: The OSV-Scanner workflow checks dependencies against the OSV database on pull requests targeting
main, on pushes tomainand weekly, and reports findings to the Security tab - Supply chain scorecard: The OpenSSF Scorecard workflow audits the repository's supply chain posture and reports findings to the Security tab
- Private vulnerability reporting: Enabled, so vulnerabilities can be reported privately through the Security tab as described above
- Branch protection: The
mainbranch is covered by a ruleset that requires changes to arrive by pull request with theAll Checks Passstatus check green and CodeQL results carrying no new alert, and blocks branch deletion and force pushes
We accept security reports in English.