aihub 1.0.0 is the first release of this client-only tree.
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
If you are on an older 2.x artifact from the former monorepo, upgrade to 1.0.0 before reporting a vulnerability.
Do NOT open a public GitHub issue for security vulnerabilities.
Please report suspected vulnerabilities privately via GitHub Security Advisories.
- Subject prefix:
[SECURITY] aihub - <short summary>
Include the following:
- aihub version and affected module (
aihuboraihub-spring-boot-starter) - JDK version and runtime environment
- Provider / platform involved (OpenAI, Anthropic, DashScope, Ollama, etc.)
- Minimal reproduction steps
- Impact assessment and any known mitigations
| Stage | Target |
|---|---|
| Acknowledgement | within 24 hours of report |
| Initial assessment | within 72 hours |
| Fix or mitigation | within 30 days for high severity, 90 days for medium/low |
| Public disclosure | after a fix is released, or after 90 days from report (Coordinated Disclosure) |
In scope:
- Vulnerabilities in aihub source that allow credential leakage, request forgery, or denial of service when the library is used as documented.
- Supply-chain concerns in published artifacts under
com.whalealon Maven Central.
Out of scope:
- Vulnerabilities in upstream LLM provider APIs.
- Issues that require the application to already have been compromised.
- Rate limiting, billing, or quota enforcement on the provider side.
- Security of RAG / MCP / Agent systems you build on top of this client.
- Never hard-code API keys in source files, tests, or configuration committed to version control.
- Treat model
tool_callsas untrusted instructions: this client parses the protocol fields; your application decides what to execute. - Do not log full Authorization headers or API keys.