Security fixes are provided for the latest release of the hottub Python
package.
Email feedback@joinhottub.com with [security: hottub-python] in the subject
and include reproduction steps and the affected version.
Do not open a public GitHub issue for a suspected vulnerability. Do not include Hottub access tokens, passwords, recovery codes, personal information, or other secrets in reports, examples, logs, or test fixtures.
We aim to acknowledge reports within 48 hours and fix critical issues within 7 days.
This repository contains a small API client and CLI. It must never contain Hottub production credentials, private monorepo content, or Harmonic Engine source, algorithms, coefficients, models, benchmarks, debug state, symbols, or binary artifacts.