Skip to content

Security: A2R-Lab/GRiD

Security

SECURITY.md

Security Policy

GRiD is a research code-generation library for GPU rigid body dynamics. It generates and compiles CUDA C++ from URDF inputs; it is not a network service and does not handle credentials or untrusted remote data.

Reporting a vulnerability

If you discover a security issue (for example, a code-generation path that could be abused to emit unsafe host/device code from a crafted URDF), please report it privately rather than opening a public issue:

  • Use GitHub's "Report a vulnerability" flow on the Security tab, or
  • Contact the A2R Lab maintainers directly.

Please include a description, reproduction steps, and the affected commit. We will acknowledge the report and work with you on a fix and disclosure timeline.

Supported versions

GRiD is developed on the main line (currently versioned 0.5.0 in pyproject.toml); only the latest release/development tip is supported — fixes land on the current development branch.

There aren't any published security advisories