Skip to content

Security: MichaelCSHN/CamoGED

Security

SECURITY.md

Security policy

Supported status

CamoGED is a research preview. Only the current default branch and the latest tagged release, when one exists, receive security fixes.

Private reporting

Do not open a public issue for vulnerabilities, exposed credentials, private data, or details that would materially lower the cost of attacking a deployed perception system.

Report privately by email to michaelcshn@gmail.com with the subject CamoGED security report. Include the affected component, reproduction conditions, impact, and whether public disclosure is time-sensitive. Encrypt sensitive attachments or request an alternate transfer method before sending them.

The maintainer will acknowledge a credible report as soon as practical, classify its scope, and coordinate remediation and disclosure. No fixed response-time SLA is promised for this unfunded research preview.

In scope

  • dependency or deployment vulnerabilities in the website, package, or CI;
  • accidental redistribution of restricted data or personal information;
  • credential or secret exposure;
  • metric or leaderboard behavior that creates a material integrity failure;
  • directly deployable bypass details affecting a real system.

Out of scope

  • disagreement with research conclusions;
  • expected limitations already labeled experimental;
  • generic reports without a reproducible affected path;
  • requests for operational attack recipes.

There aren't any published security advisories