librarian

Security Policy

Supported Versions

Librarian 1.x receives security fixes on main and through patch releases when a fix affects a published release.

Reporting A Vulnerability

Do not open a public issue for suspected vulnerabilities.

Email security reports to security@nampara.ai with:

We will acknowledge reports within 5 business days and coordinate a fix or disclosure plan.

Secret Handling

Threat Model

See docs/OPERATIONS.md for the current operational security guidance covering API imports, archive policy, provider data flow, logging, SQLite operations, and hosted-mode risks.

Dependency Security

GitHub Dependabot and CodeQL are enabled for baseline dependency and code scanning. Maintainers should review dependency alerts before cutting releases.