voxigo is in early development and its version stays in the 0.0.x range. Only
the latest release receives security fixes; there are no long-term-support
branches yet. The supported surface will be revisited once 0.1.0 ships.
| Version | Supported |
|---|---|
latest 0.0.x |
✅ |
| older | ❌ |
Please report security vulnerabilities privately — do not open a public issue, pull request, or discussion for them.
Use GitHub's private vulnerability reporting:
- Go to the repository's Security tab.
- Click Report a vulnerability (direct link).
- Describe the issue, including affected versions and, where possible, a minimal reproduction.
We aim to acknowledge a report within a few business days and will keep you updated as we investigate and prepare a fix. Once a fix is available we will coordinate disclosure and credit you in the advisory, unless you prefer to remain anonymous.
voxigo is a library and a set of example bots. Vulnerabilities in voxigo's own code — the pipeline, transports, providers, and audio handling — are in scope. Issues in upstream dependencies, the underlying ONNX Runtime, or third-party provider APIs should be reported to those projects, though we welcome a heads-up if voxigo's use of them is affected.