Skip to content

Security: Sris945/SAGE

Security

SECURITY.md

Security Policy

Supported Versions

SAGE is currently under active development. Security updates and fixes are applied to the latest version of the project.

Older versions may not receive security updates.

Version Supported
Latest
Older versions

Reporting a Vulnerability

If you discover a security vulnerability in SAGE, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

Instead, report it privately by contacting the maintainer:

📧 Email: your-email@example.com
or
📩 Open a private security advisory on GitHub.

Please include the following information in your report:

  • Description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact
  • Suggested fix (if available)

Responsible Disclosure

We ask that you:

  • Give us reasonable time to investigate and patch the issue
  • Avoid publicly disclosing the vulnerability until a fix is released
  • Work with the maintainers to resolve the issue responsibly

Security Best Practices

Users of SAGE should:

  • Avoid running unknown code generated by the system without review
  • Run SAGE in a controlled development environment
  • Use containerization or sandboxing for execution when possible

Acknowledgements

We appreciate responsible disclosure and will acknowledge contributors who help improve the security of the project.

There aren’t any published security advisories