If you discover a security vulnerability in CorridorKey Runtime, please report it responsibly. Do not open a public GitHub issue.
Send an email to alexandre.alvaro@hotmail.com with:
- A description of the vulnerability
- Steps to reproduce the issue
- The potential impact
- Any suggested fix (optional)
- Acknowledgement within 72 hours of your report
- Status update within 14 days with an assessment and remediation plan
- Credit in the fix commit and release notes (unless you prefer anonymity)
This policy covers the CorridorKey Runtime codebase, including:
- The inference engine and all execution providers
- File I/O modules (EXR, PNG, video)
- CLI and GUI applications
- OFX plugin integration
- Build system and dependency configuration
- Vulnerabilities in upstream dependencies (ONNX Runtime, FFmpeg, etc.) should be reported to those projects directly
- Issues in third-party model files
Security fixes are applied to the latest release only. We do not maintain long-term support branches.