Skip to content

Security: liyi-run/liyi

Security

SECURITY.md

Security Policy

Status

立意 (Lìyì) is in early development (v0.1, pre-release). The tool runs locally, performs no network access, and processes only local files and .liyi.jsonc sidecars. Its attack surface is limited to malformed input files.

Reporting a Vulnerability

If you discover a security issue, please report it by opening a GitHub Security Advisory on this repository.

Please do not file a public issue for security vulnerabilities.

Response Expectations

This project is maintained part-time by a solo developer. Please expect:

  • Acknowledgement within 7 days.
  • Resolution timeline communicated within 14 days, though fixes for genuine vulnerabilities will be prioritised over other work.

Supported Versions

Only the latest commit on main is supported during this pre-release phase.

There aren’t any published security advisories