Security fixes are currently evaluated for the latest code on public main and the
0.10.0 Alpha public-preview line. Historical tags are retained for evidence and are not
promised maintenance branches. OMIV is pre-1.0 and this scope may change with a
documented release policy.
Live GitHub visibility and security-control read-back are authoritative. The controlled R1F transaction verified Private Vulnerability Reporting, secret scanning, push protection, and the reviewed main protection while the repository was public. Use the repository's Security → Report a vulnerability flow for sensitive reports. This channel is a repository security control, not a claim of safety certification, publisher authenticity, or production readiness. If the control is unavailable, do not disclose sensitive details through a public issue or another public fallback.
The prior public interval lasted approximately 5 hours 39 minutes. The pre-public audit found no secret or privacy finding, but returning PRIVATE cannot erase prior observation, indexing, links, caches, copies, watchers, forks, or repository-network effects. No claim is made that no third party observed or copied the repository. No tag, GitHub Release, PyPI publication, or announcement occurred.
Do not put vulnerability or exploit details in a public issue. If the Report a vulnerability control is unavailable, do not use a public issue as a fallback; it must not contain reproduction steps, credentials, customer data, private payloads, signed URLs, or other details of an unpatched vulnerability.
Do not send credentials, access tokens, cookies, private keys, customer data, production prompts or outputs, private model metadata, or model/tokenizer payloads. Use minimal synthetic reproduction material and remove signed URLs and raw HTTP headers. No response or remediation SLA is promised.
OMIV evidence validates explicitly recorded properties. A successful parse, signature check, or policy result is not a safety certification and does not establish that a model is secure, authentic, production-ready, or suitable for regulated use.