Skip to content

Security: cohere-ai/cvm-measure

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest release of cvm-measure is supported with security updates. We recommend always running the most recent version.

Reporting a Vulnerability

Please do NOT open a public GitHub issue for security vulnerabilities.

If you discover a security vulnerability in cvm-measure, please report it through one of the following channels:

What to Include

To help us triage and resolve the issue quickly, please include:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • An assessment of the potential impact (e.g., data exposure, privilege escalation, denial of service)
  • Any relevant logs, screenshots, or proof-of-concept code

Response Timeline

  • We will acknowledge your report within 3 business days.
  • We aim to resolve critical issues within 30 days of acknowledgment.
  • We will keep you informed of our progress throughout the process.

We appreciate your help in keeping cvm-measure and its users safe.

There aren't any published security advisories