Files
pyscn/SECURITY.md

732 B

Security Policy

We take security seriously and appreciate responsible disclosure of vulnerabilities.

Reporting a vulnerability:

  • Prefer GitHub Security Advisories: open a private report under the "Security" tab of the repository.
  • If you cannot use advisories, open a minimal issue without sensitive details and request a maintainer to start a private thread.

Please include:

  • A clear description of the issue and impact
  • Steps to reproduce (PoC) and affected versions/platforms
  • Suggested mitigations if known

We aim to acknowledge reports within 3 business days and provide status updates until resolution.

Do not disclose vulnerabilities publicly until a fix is released and coordinated disclosure has been agreed.