| Package | Supported versions |
|---|---|
logion-client (Python SDK) |
Latest minor release |
logion-cli |
Latest minor release |
logion-agent-companion |
Latest minor release |
Only the latest minor version of each package receives security patches.
Do not file a public issue for a security vulnerability.
Instead, please use one of these private channels:
- Preferred: Open a private vulnerability report at
https://github.com/nicolasmelo1/logion/security/advisories/new - Fallback: Email security@logion.sh
You can expect an initial response within 72 hours.
We follow a 90-day disclosure window. After a vulnerability is confirmed, we will:
- Prepare a fix and coordinate a release.
- Credit the reporter (unless they prefer to remain anonymous).
- Publish the advisory after the fix is released.
The disclosure window may be shortened by mutual agreement between the maintainer and the reporter.
In scope:
- The public packages published from this repository:
logion-client,logion-cli, andlogion-agent-companion. - The OpenAPI contract at
contracts/openapi/v1.jsonas shipped in this repository.
Out of scope:
- Rate limiting on public endpoints (intentional design).
- Reports that require physical access to infrastructure.
- Social-engineering attacks.
- Denial-of-service attacks against public endpoints.
If you discover a vulnerability in the backend services that power the Logion platform, please report it through the same channels above and we will route it to the appropriate team internally.