Case library

Real cases.
Useful questions.

Selected advisories, incidents, release fixes and documented behaviours explain deployment conditions and responses. Counts reflect editorial selection, not vendor security rankings.

Sources reviewed 2026-10-07 · By OneQuill Research

16 cases

Incident report

LiteLLM

LiteLLM: package provenance and incident response

Malicious PyPI distributions, distinct from the vendor's official pinned Proxy Docker images

Remediation record: Vendor describes a clean 1.83 release and pipeline v2 on 30 March; incident response also requires containment and credential review.

Reviewed 2026-10-07Read case →
Security advisory

SGLang

SGLang: isolate worker channels and model-management paths

Feature-dependent worker serialization, replay tooling and administrative/model-loading interfaces

Remediation record: March CERT/CC update: 0.5.10, with conflicting CVE-2026-3059 metadata. A fixed release for the July group is not established by the cited July notice.

Reviewed 2026-10-07Read case →

How to read this research

Evidence with a defined scope.

Product coverage is a researched snapshot, not an exhaustive inventory. Category and deployment mode describe the cited offering; editions, contracts and configuration can change the scope. Selected cases illustrate evaluation questions. Advisory counts are not security rankings.

Security advisory

A published security finding, with prerequisites and remediation evidence.

Incident report

A reported event and response, attributed to its source.

Release fix

A correction recorded in release notes; not automatically a CVE.

Documented behaviour

A design choice, default or limit from official documentation.

Published by OneQuill, developer of OneVir. This is a documentary review of selected public sources, not an independent vendor security audit. Published 2026-10-07 · Modified 2026-10-07 · Sources reviewed 2026-10-07.

Report corrections through OneQuill support, with the page and primary source. Download research records (JSON) · Publishing method and templates.

A practical next step

Take the questions into your review.

Six A4 pages. Record the provider, version, configuration, evidence, owner and action for each topic.