We provide security updates for the latest stable release of RAGForge.
| Version | Supported |
|---|---|
| v1.0.x | ✅ |
| < v1.0 | ❌ |
If you discover a potential security vulnerability in RAGForge, please do not report it through a public GitHub issue.
Instead, please send a detailed security report via email to security@ragforge.org or submit a private security advisory through GitHub.
- Type of vulnerability (e.g., prompt injection, credential exposure, path traversal).
- Step-by-step instructions to reproduce the issue.
- Affected components (e.g., API endpoints, specific plugins).
- Any potential mitigations or suggested fixes.
We aim to respond to security reports within 48 hours and provide periodic updates until the vulnerability is addressed.