Only the latest release of cvm-measure is supported with security updates. We recommend always running the most recent version.
Please do NOT open a public GitHub issue for security vulnerabilities.
If you discover a security vulnerability in cvm-measure, please report it through one of the following channels:
- GitHub Security Advisory (preferred): Create a private security advisory
- Email: inference-confidential-computing@cohere.com
To help us triage and resolve the issue quickly, please include:
- A clear description of the vulnerability
- Steps to reproduce the issue
- An assessment of the potential impact (e.g., data exposure, privilege escalation, denial of service)
- Any relevant logs, screenshots, or proof-of-concept code
- We will acknowledge your report within 3 business days.
- We aim to resolve critical issues within 30 days of acknowledgment.
- We will keep you informed of our progress throughout the process.
We appreciate your help in keeping cvm-measure and its users safe.