Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, report them privately through one of these channels:
- Email: security@truefoundry.com
- GitHub: use private vulnerability reporting on this repository
Please include as much of the following as you can:
- A description of the vulnerability and its impact
- Steps to reproduce, or a proof of concept
- Affected versions or deployment modes (standalone / multi-replica / Helm)
- Any suggested mitigations
- We will acknowledge your report within 3 business days.
- We will keep you informed as we investigate and work on a fix.
- We will credit you in the release notes when the fix ships, unless you prefer to remain anonymous.
Security fixes are applied to the latest release. We recommend always running the most recent version.