Only the main branch and the most recent published ocr-service image receive security fixes.
Report vulnerabilities privately through GitHub security advisories. Do not open a public issue or pull request for a suspected vulnerability.
Include the affected component, a reproduction, and the impact you believe it has. Never include real customer documents, credentials, or production data in a report.
We acknowledge reports within three business days, aim to ship a fix within ninety days, and credit reporters in the advisory unless they ask otherwise.
The threat model, trust boundaries, and known non-goals are documented in
docs/security/THREAT-MODEL.md. Findings that
fall inside a documented non-goal are still welcome as issues, but are not
treated as vulnerabilities.