SecResearch actively supports the latest release with security updates and bug fixes.
| Version | Supported |
|---|---|
| 0.2.x | ✅ |
| < 0.2.0 | ❌ |
We take the security and integrity of SecResearch seriously. If you discover a potential security vulnerability, please report it responsibly:
- Private Disclosure: Do not open a public issue. Please submit a security report via GitHub Private Vulnerability Reporting or contact the maintainers directly.
- Details to Include:
- Description of the vulnerability.
- Steps to reproduce or proof-of-concept.
- Potential impact and affected components (CLI, Extractor, FastMCP server, Storage).
- Response Timeline:
- Initial acknowledgement: Within 48 hours.
- Remediation and patch release: Prioritized based on severity.
SecResearch only accesses public, peer-reviewed, open-access, and public-domain academic repositories (USENIX, NDSS, IACR, arXiv, NIST). It respects robots.txt, applies polite request rates, and never bypasses authentication mechanisms or paywalls.