Skip to content

Security: MusaShams/layerrag-bench

Security

SECURITY.md

Security Policy

Supported version

Security fixes are maintained for the current public release line:

Version Supported
1.0.x Yes
Earlier private development versions No public support commitment

Reporting a vulnerability

Do not open a public issue for suspected vulnerabilities, leaked credentials, tenant-isolation failures, authorization bypasses, or exposure of private model traces.

Use GitHub's private vulnerability reporting feature when it is enabled for this repository. If private reporting is unavailable, contact the repository owner privately through their GitHub profile before sharing technical details.

Include:

  • the affected version or commit;
  • the impacted reliability layer;
  • reproduction steps;
  • potential data or credential exposure;
  • suggested mitigations, when available.

Scope

LayerRAG is a research benchmark and reference reliability implementation. It does not certify production authorization, privacy, tenant isolation, or regulatory compliance. Host applications remain responsible for trusted identity, access-control enforcement, secure credential storage, network controls, and authoritative data sources.

There aren't any published security advisories