Skip to content

Security: evertonsjjj/vouch

Security

SECURITY.md

Security policy

Reporting a vulnerability

If you discover a security vulnerability in vouch, please do not open a public issue. Instead, email the maintainer at the address listed on the package's PyPI page, or open a private security advisory on GitHub:

https://github.com/evertonsjjj/vouch/security/advisories/new

Please include:

  • A description of the issue and impact
  • Steps to reproduce
  • Affected versions

We aim to acknowledge reports within 72 hours and ship a fix in the next patch release. For coordinated disclosure, suggest your preferred timeline.

Supported versions

Only the latest minor release receives security fixes. Older versions are best-effort.

Version Supported
0.2.x
0.1.x ⚠️ best-effort

There aren't any published security advisories