If you discover a security vulnerability in Timber, please report it privately.
- Email: kossi@electricsheep.africa
- Subject: [Timber Security]
Please include:
- A clear description of the issue
- Steps to reproduce
- Affected version(s)
- Potential impact
- Any suggested mitigation
- We will acknowledge receipt within 72 hours.
- We will investigate and triage severity.
- We will work on a fix and coordinate responsible disclosure.
- We will publish a security advisory once a patch is available.
| Version | Supported |
|---|---|
| 0.1.x | Yes |
| < 0.1.0 | No |
Security reports are especially valuable for:
- Unsafe model artifact parsing
- Remote code execution paths in CLI/server
- Memory safety problems in generated C runtime
- Authentication/authorization issues (if introduced in future server modes)
- Supply-chain risks in build/release workflows