Skip to content

Security: sandbox-quantum/nex_public

SECURITY.md

Security Policy

Supported versions

This repository is a minimal, standalone reproduction of the methods described in the accompanying NEX publication. It is provided for research and reproducibility purposes and is not intended for production use. Only the latest state of the main branch is maintained.

Reporting a vulnerability

If you discover a security vulnerability, please do not open a public issue. Instead, report it privately using GitHub's private vulnerability reporting for this repository (Security tab → "Report a vulnerability").

We will acknowledge your report and work with you to understand and address the issue.

Security considerations for users

Pickle files (.pkl)

This project writes Python pickle files (for example nex_switch_store.pkl) via pickle.dump in nex/switching.py. Some utilities (e.g. scripts/compute_free_energy.py) read these files with pickle.load.

Deserializing a pickle file executes arbitrary code. Only load .pkl files that you generated yourself or obtained from a trusted source. Never load a pickle file from an untrusted or unverified third party.

The .npz archives (e.g. under data/fig3/) are loaded with np.load(..., allow_pickle=False) and do not carry this risk.

Dependencies

Dependencies are declared in environment.yml and pyproject.toml. Some are loosely pinned for demonstration convenience; pin exact versions if you need a reproducible, supply-chain-hardened environment.

There aren't any published security advisories