Skip to content

Security: AndresCdo/kan-rust

Security

SECURITY.md

Security Policy

Supported Versions

We take security seriously and strive to ensure that the Kolmogorov-Arnold Network (KAN) project is secure. We will actively address security vulnerabilities in the following versions:

Version Supported
1.x
< 1.0

Reporting a Vulnerability

If you discover a security vulnerability, please do the following:

  1. Do Not Publicly Disclose: Do not file a public issue or pull request. Security vulnerabilities should not be discussed in public forums until they are resolved.
  2. Contact Us Privately: Send a detailed email to the project maintainers at AndresCdo. Include the following information:
    • A detailed description of the vulnerability.
    • Steps to reproduce the vulnerability.
    • Potential impact and severity of the vulnerability.
    • Any potential fixes or suggestions for mitigating the issue.

Handling of Security Vulnerabilities

Upon receiving a security report, we will:

  1. Acknowledge Receipt: Confirm receipt of your report within 48 hours and provide an estimated timeline for addressing the issue.
  2. Investigate: Investigate the vulnerability to verify its validity and determine the impact.
  3. Mitigation Plan: Develop a plan to mitigate and fix the vulnerability.
  4. Patch and Release: Apply the necessary patches and release a new version. We aim to release security fixes as quickly as possible.
  5. Public Disclosure: After the patch is released, we will publicly disclose the vulnerability, including details and the steps taken to address it.

Security Best Practices

We encourage users and contributors to follow these security best practices:

  • Keep Dependencies Updated: Regularly update dependencies to the latest versions.
  • Code Reviews: Conduct thorough code reviews to identify potential security issues.
  • Testing: Implement and run comprehensive tests to ensure code changes do not introduce vulnerabilities.
  • Principle of Least Privilege: Design and implement features with the principle of least privilege in mind, limiting access and permissions as much as possible.

Security Contact

For any security-related inquiries or to report a vulnerability, please contact the maintainers at AndresCdo.

Thank you for helping to keep the Kolmogorov-Arnold Network (KAN) project secure!

There aren’t any published security advisories