This repository accepts security reports for:
- Python package runtime and CLI (
src/zpe_image_codec,zpe-image-verify). - Verification, proof, and validation artifacts (
proofs/,validation/). - CI and release pipeline configurations.
Please report vulnerabilities privately to architects@zer0pa.ai with:
- A clear impact summary.
- Reproduction steps or proof-of-concept.
- Affected versions or commit ranges.
- Suggested remediation when available.
- Initial acknowledgement: within 5 business days.
- Triage and severity classification: within 10 business days.
- Remediation timeline: shared after triage.
Public disclosure should be coordinated after a fix is available.