Only the most recent minor release line receives security fixes. Older versions are end-of-life and will not receive patches.
| Version | Supported |
|---|---|
| 0.3.x | ✅ |
| < 0.3 | ❌ |
Releases before 0.3.0 were published under the working name marginalia
and are not supported.
If you believe you have found a security vulnerability in okto-neuron,
please report it privately so we can work on a fix before it becomes
public. Please do not open a public GitHub issue for vulnerability
reports.
Use GitHub's private vulnerability reporting feature on this repository: https://github.com/OktoLabsAI/okto-neuron/security/advisories/new
If you cannot use GitHub's reporting flow, email security@oktolabs.ai with:
- a description of the vulnerability and its impact,
- steps to reproduce (proof-of-concept welcome),
- any version, configuration, or environment details that affect the attack surface,
- whether you intend to publish your own write-up, and on what timeline.
- Acknowledgement within 2 business days of receipt.
- Initial triage and severity assessment within 5 business days.
- Fix timeline depends on severity:
- Critical: target patch within 7 days.
- High: target patch within 14 days.
- Medium / Low: rolled into the next normal release.
- We aim to coordinate disclosure with the reporter. Public disclosure happens after a fix ships, unless an in-the-wild exploit forces an earlier announcement.
In scope:
- Code in this repository (Python package, CLI, MCP and REST server, web UI bundle).
- The installers in this repository (
install.sh,install.ps1at the repository root) and the release manifest they verify. - Wheels published as GitHub Release assets of this repository and on PyPI
as
okto-neuron. - Default configuration shipped with the above.
Out of scope:
- Third-party dependencies (please report upstream first; if you believe our usage compounds the issue, include that in the report).
- Model providers and endpoints you configure yourself.
- User-deployed instances we do not operate.
- Social-engineering attacks against project maintainers.
By submitting a report you agree to give us a reasonable window to patch before any public discussion. We will credit reporters who wish to be credited once a fix has shipped.
- Contributing Guide: general contribution flow.
- CLA: required for accepted code contributions.