GraphRAG is currently pre-1.0. Security fixes are applied to the latest commit on main; older commits and forks are not maintained as supported release lines.
Please do not open a public issue for a suspected vulnerability.
Use the repository's Security tab and choose Report a vulnerability to submit a private report. Include:
- the affected component and commit;
- the prerequisites and reproduction steps;
- the expected and observed behavior;
- the likely impact; and
- any suggested remediation or supporting logs with secrets removed.
You should receive an acknowledgement within seven days. A validated issue will be investigated privately, fixed on the supported branch, and disclosed after users have a reasonable opportunity to update.
If a real OpenRouter key, session secret, internal token, database credential, or encryption key is exposed, revoke or rotate it immediately before attempting to remove it from code or Git history. Treat a credential as compromised even if the commit was quickly deleted or force-pushed.
Never include private documents, prompts, API keys, session cookies, or unredacted production logs in a vulnerability report.