| Version | Supported |
|---|---|
| Latest | ✅ |
| < 1.0 | ❌ |
Do not open a public GitHub issue for security vulnerabilities.
Email security@stemsplit.io with:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
We will respond within 48 hours and aim to release a fix within 7 days.
This policy covers the demucs-onnx Python package and its ONNX model inference code. It does not cover the StemSplit hosted API (report those to security@stemsplit.io separately).