Release notes for Local RAG are published with GitHub Releases:
https://github.com/jonfairbanks/local-rag/releases
When a release fixes a publicly known runtime vulnerability in Local RAG that already has a CVE or similar public identifier at release time, the release notes identify that vulnerability and summarize the upgrade impact.
If a release has no such vulnerability fixes, the release notes may omit this section.
Local RAG release tags use semantic versioning, for example v1.4.3.