| Version | Supported |
|---|---|
| latest | Yes |
If you discover a security vulnerability, please report it responsibly. For issues that do not require private disclosure, please open a GitHub issue.
For sensitive security issues that require private disclosure, please contact the maintainer directly.
Please include:
You should receive a response within 72 hours. Security fixes will be prioritized and released as soon as possible.
CoralAPI ships without authentication or rate limiting by design — it is meant to run behind an authenticated gateway or ingress that provides those. See the Security model section of the README for the full posture. In summary:
CORALAPI_MODEL_CHECKSUMS). Point CORALAPI_MODEL_SOURCE only at a source you trust; models are loaded onto the TPU.CORALAPI_MAX_UPLOAD_BYTES and CORALAPI_MAX_IMAGE_DIM for your environment.