Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Preferred channel: GitHub private vulnerability reporting — use "Report a vulnerability" under this repository's Security tab. You'll get an acknowledgement within 3 business days.
If you can't use GitHub reporting, email
hello@littlebigbrain.com with
SECURITY in the subject line.
Please include a description of the issue, the affected
lbb version, and a proof of concept or reproduction
steps if you have one.
- The published package
littlebigbrain(PyPI) and the source in this repository. - For issues in the hosted little big brain service itself
(
*.littlebigbrain.com), use the same channels — they reach the same team.
The SDK is in beta (0.x). Only the latest released version receives
security fixes; fixes ship as a new patch release rather than as patches to
old versions.
We follow coordinated disclosure: we'll work with you on a fix and release, and credit you in the advisory unless you prefer otherwise. Please give us a reasonable window to ship a fix before publishing details.