We take the security of Ragas Java seriously. If you discover a security vulnerability in this project, please report it privately. Do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
To report a vulnerability, email founders@vibrantlabs.com. Please include as much information as possible:
- Type of issue (for example, SSRF, deserialization, injection)
- Affected versions
- Affected files or modules
- Location in code (tag, branch, commit, or URL)
- Configuration details required to reproduce
- Environment (OS, Java version)
- Reproduction steps
- Proof-of-concept or exploit code, if possible
- Impact assessment and suggested mitigation
The following versions of Ragas Java are currently supported with security updates:
| Version | Supported |
|---|---|
| 0.1.x | Yes |
| < 0.1.x | No |
Upon receiving a security report, we will:
- Acknowledge receipt within 48 hours.
- Investigate and verify the issue.
- Develop a fix and prepare a release.
- Coordinate with the reporter to validate the fix.
- Release the fix and update all affected parties.
We aim to address critical issues within 7 days of disclosure.
We prefer all communications to be in English.
We follow the principle of Coordinated Vulnerability Disclosure.
- GitHub's Guide to Reporting Security Vulnerabilities
- Open Source Security Foundation (OpenSSF) Best Practices
This policy is subject to change without notice. Please refer to the latest version in this repository.