Only the latest release of VasukiSquare receives security updates and vulnerability patches.
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
| < 0.1.0 | ❌ |
If you discover a security vulnerability in VasukiSquare, please report it responsibly:
- Open a confidential security advisory or contact the repository maintainers through the official repository contact channels.
- Please provide a detailed description of the vulnerability, reproduction steps, and potential impact.
- Do not create public GitHub issues for sensitive security vulnerabilities.
- Never commit
.envor.env.localfiles to version control. The.gitignorefile is configured to exclude these files by default. - Use environment variables or local
.envfiles forGROQ_API_KEY,TAVILY_API_KEY,SERPER_API_KEY, andMONGODB_URI. - If an API key is ever committed or exposed accidentally, rotate and invalidate it immediately via your provider console.
- When using Ollama (
LLM_PROVIDER=ollama), ensure the Ollama API port (11434) is bound tolocalhost(127.0.0.1) and not exposed to the public internet without an authentication proxy.
- When connecting to MongoDB instances in production environments, use TLS/SSL connection strings and ensure strong authentication is enforced.