| Version | Supported |
|---|---|
0.2.x (main) |
Yes — security fixes preferred on main |
< 0.2 |
Best-effort only |
Please do not open a public GitHub issue for security-sensitive reports.
- Email or privately message the maintainer listed in
CODEOWNERS, or - Use GitHub Security Advisories → Report a vulnerability on KanakMalpani/Binary-Neural-Networks if enabled.
Include: affected version / commit, repro steps, impact, and (if available) a minimal PoC.
We aim to acknowledge within 7 days and ship a fix or mitigation advisory when confirmed.
- Prefer
weights_only=True(or equivalent) fortorch.loadof untrusted checkpoints. .bnnpackloads go throughbnn.codec.load_bnnpackwith no unsafe pickle fallback; path soft-warnings viabnn.paths.warn_untrusted_packwhen the file sits outside labresults//checkpoints//data/(W10.T03 / W10.T06).- Do not commit secrets, API keys, or datasets under
data/. - Native kernels are local DLLs/SOs built from this tree — treat third-party binaries as untrusted.
Reports that only claim “GPU 32× from sign()” are thesis violations, not security bugs —
see ROADMAP.md §0.2. Open a thesis-violation issue template instead.