Report vulnerabilities to security@cocoindex.io — please do not open public issues. Include a description, reproduction steps, and any relevant logs or proof-of-concept.
Process, response SLAs, and disclosure terms are defined in the CocoIndex organization security policy.
Scope: CocoIndex Code (open source) — this repository and the PyPI
package cocoindex-code. Security fixes land in the latest release.