Skip to content

Security: verkiki/quantbridge

Security

SECURITY.md

Security Policy

Report security-sensitive problems privately to the repository maintainer before opening a public issue.

QuantBridge reads untrusted model metadata and can create very large files. It therefore validates paths, avoids shell execution, refuses overwrites, caps Safetensors header size, disables remote code by default, and leaves failed outputs visible for inspection.

Do not include model weights, access tokens, credentials, or private filesystem paths in reports. Use the smallest synthetic reproduction possible.

There aren't any published security advisories