| Version | Supported |
|---|---|
Latest 0.x release |
Yes |
| Older releases | No |
Do not report suspected vulnerabilities in a public GitHub issue, pull request, discussion, or community chat.
Use GitHub's private vulnerability reporting flow:
Report a vulnerability privately
Include:
- A description of the vulnerability and its potential impact
- The affected Graphiti version, component, and configuration
- Reproduction steps or a proof of concept
- Any known mitigations or workarounds
- Whether the vulnerability has been disclosed elsewhere
Remove real credentials, customer data, and other sensitive information from the report.
Maintainers will acknowledge the report as soon as practical, assess its impact, and coordinate remediation and disclosure with the reporter. Please allow maintainers time to investigate and release a fix before sharing details publicly.