Security fixes are maintained for the current public release line:
| Version | Supported |
|---|---|
| 1.0.x | Yes |
| Earlier private development versions | No public support commitment |
Do not open a public issue for suspected vulnerabilities, leaked credentials, tenant-isolation failures, authorization bypasses, or exposure of private model traces.
Use GitHub's private vulnerability reporting feature when it is enabled for this repository. If private reporting is unavailable, contact the repository owner privately through their GitHub profile before sharing technical details.
Include:
- the affected version or commit;
- the impacted reliability layer;
- reproduction steps;
- potential data or credential exposure;
- suggested mitigations, when available.
LayerRAG is a research benchmark and reference reliability implementation. It does not certify production authorization, privacy, tenant isolation, or regulatory compliance. Host applications remain responsible for trusted identity, access-control enforcement, secure credential storage, network controls, and authoritative data sources.