Security fixes land on the latest minor of the current major version. Older majors are supported for six months after the next major ships; after that, upgrade to receive fixes.
Report vulnerabilities privately to kai@canarycoders.es. Do not open a public issue for security problems.
Include what you can: affected version, reproduction steps or a proof of concept, and impact. You will get an acknowledgement within 2 business days and a status update within 14 days. Please give us reasonable time to ship a fix before public disclosure; we credit reporters in the release notes unless you prefer otherwise.
This policy covers the @canarycoders/ai npm package. Vulnerabilities in the CanaryAI API
service itself can be reported to the same address.