Skip to content

Security: PB811/GraphRAG

SECURITY.md

Security policy

Supported versions

GraphRAG is currently pre-1.0. Security fixes are applied to the latest commit on main; older commits and forks are not maintained as supported release lines.

Report a vulnerability

Please do not open a public issue for a suspected vulnerability.

Use the repository's Security tab and choose Report a vulnerability to submit a private report. Include:

  • the affected component and commit;
  • the prerequisites and reproduction steps;
  • the expected and observed behavior;
  • the likely impact; and
  • any suggested remediation or supporting logs with secrets removed.

You should receive an acknowledgement within seven days. A validated issue will be investigated privately, fixed on the supported branch, and disclosed after users have a reasonable opportunity to update.

Exposed credentials

If a real OpenRouter key, session secret, internal token, database credential, or encryption key is exposed, revoke or rotate it immediately before attempting to remove it from code or Git history. Treat a credential as compromised even if the commit was quickly deleted or force-pushed.

Never include private documents, prompts, API keys, session cookies, or unredacted production logs in a vulnerability report.

There aren't any published security advisories