Files
heuropt/SECURITY.md
T
swaits 6371d82f40 docs(0.9): release notes, cookbook recipe, README polish
Companion to the feat(explorer) commit. Bumps the version and
brings every cross-referencing doc up to v0.9 currency.

- Cargo.toml: version 0.8.0 -> 0.9.0.
- CHANGELOG: 0.9.0 entry covering the explorer export, the
  Problem-side metadata additions, the AlgorithmInfo trait, the
  pick_a_car example, and the new cookbook recipe.
- README: closing paragraph of the PickACar example points users
  at the explorer with a one-call snippet
  (`ExplorerExport::from_result(...).with_algorithm_info(...)
  .to_file(...)?`). Version snippets bumped 0.8 -> 0.9.
- New cookbook recipe at docs/book/src/cookbook/explorer.md
  covering: enabling the serde feature, enriching Problem with
  labels/units/decision-schema, the export call, the JSON schema,
  and custom decision-type handling.
- SUMMARY.md and cookbook.md link the new recipe.
- migration.md: new "To 0.9" section documenting the additive
  changes (purely backwards-compatible upgrade from 0.8.x).
- introduction.md, comparison.md, choosing-an-algorithm.md,
  stability.md: version refs bumped 0.8 -> 0.9.
- cookbook/parallel.md, cookbook/async.md: version refs bumped
  0.8 -> 0.9.
- getting-started.md: version refs bumped, serde feature
  description expanded to mention the explorer module.
- SECURITY.md: supported-versions table moves to 0.9.x.
2026-05-06 22:45:59 -06:00

2.2 KiB

Security policy

Supported versions

Security fixes are applied to the latest released minor version on crates.io. Patch-level releases (0.x.y0.x.y+1) are issued as needed.

Version Supported
0.10.x
≤ 0.9.x (please upgrade)

heuropt is pre-1.0; the public API may change between minor versions. Once 1.0.0 ships, the support window will be at least the latest two minor versions.

Reporting a vulnerability

Please do not open a public GitHub issue for a security bug. Instead use one of these channels:

Please include:

  1. A description of the vulnerability and the affected versions.
  2. The smallest reproducer you can produce — a cargo run --example repro is ideal.
  3. Your assessment of impact and exploitability.
  4. Any suggested mitigation if you have one.

What I will do

  • Acknowledge the report within 72 hours.
  • Confirm or refute reproducibility within 7 days.
  • Issue a fix in a patch release within 30 days for confirmed high-severity issues; less urgent issues may roll into the next minor release.
  • Credit the reporter in the CHANGELOG entry unless you ask otherwise.

What counts as a security issue

heuropt is a numerical library, not a network service or sandbox. The realistic security-relevant categories are:

  • Memory safety: any unsafe-code-related UB or unwinds-across-FFI bug. heuropt itself uses no unsafe; this category covers dependencies it transitively pulls in.
  • Denial of service: an input to a public API that causes unbounded memory growth, infinite loop, or panic outside its documented panic conditions. (Documented panics for invalid config are not bugs.)
  • Supply-chain compromise: a published heuropt crate that doesn't match the source on the tagged commit.

Functional correctness bugs (an algorithm produces wrong hypervolumes, etc.) are tracked as ordinary issues, not security.