Only the latest minor release receives security fixes. Older releases are not patched.
| Version | Supported |
|---|---|
main |
yes |
latest tagged release (v0.x) |
yes |
| older tags | no |
Please do not open a public GitHub issue for security problems.
The preferred channel is GitHub Security Advisories (private vulnerability reporting):
- Go to https://github.com/JadenRazo/llm-lint/security/advisories/new
- Describe the issue, expected impact, and reproduction steps
- We will respond within 5 business days with an initial acknowledgement and a triage timeline
If GitHub Security Advisories is unavailable to you, email jadenscottrazo@gmail.com with the same information. Please use a clear subject line such as [llm-lint security] <one-line summary>.
We follow coordinated disclosure:
- Default embargo is 90 days from initial report, or until a fix is publicly released — whichever comes first
- Embargo may be shortened if the issue is being actively exploited or already public
- We credit reporters in the release notes unless anonymity is requested
In scope:
- The
llm-lintCLI binary and Docker image (ghcr.io/jadenrazo/llm-lint) - Released artifacts on the GitHub Releases page (tarballs, checksums, signatures)
- Supply-chain integrity of the build (cosign signatures, SBOMs, GitHub Actions workflows)
Out of scope:
- Issues in third-party Go modules used by
llm-lint— please report those upstream. Renovate andgovulncheckcover known CVEs in our CI; if you find a new one, please file with the upstream project too. - Best-practice or hardening suggestions that aren't exploitable — open a regular GitHub issue or PR for those.
Any OSV exception must live in osv-scanner.toml with an evidence-based reason and an expiry date. An exception suppresses dependency-inventory noise only; the required govulncheck ./... call-analysis gate remains blocking in CI and releases.
Each release includes:
checksums.txt— SHA-256 of every archivechecksums.txt.bundle— cosign Sigstore bundle (signature + certificate in one file)*.spdx.json— SBOM per archive
Verify with:
cosign verify-blob \
--bundle checksums.txt.bundle \
--certificate-identity-regexp 'https://github.com/JadenRazo/llm-lint/.+' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
checksums.txtReleases before v0.4.0 shipped separate
checksums.txt.sigandchecksums.txt.pemfiles instead of a bundle. To verify those, swap--bundle checksums.txt.bundlefor--certificate checksums.txt.pem --signature checksums.txt.sig. The change came with cosign v3, which removed the flags that emitted the separate files.
Container images (ghcr.io/jadenrazo/llm-lint:<tag>) are signed keyless via cosign and verifiable with cosign verify against the same OIDC identity.