Do not open a public issue for a suspected vulnerability.
Use GitHub private vulnerability reporting to send the affected component, reproduction steps, impact, and any suggested mitigation directly to the maintainer.
Do not include credentials, private datasets, proprietary training data, or personal information in a report.
Security fixes are applied to the current main branch and the latest published release. Older tags may not receive separate fixes.
BuildLLM downloads and processes external corpora. Review source licenses and reports, inspect accepted and rejected documents, and do not add confidential or regulated data to a public corpus configuration.