Skip to content

Security: 06chaynes/descry

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you believe you have found a security vulnerability in Descry, please report it privately via email to 06chaynes@gmail.com with the subject line [SECURITY] <short description>.

Please do not file a public GitHub issue for security concerns.

Include in your report:

  • A description of the issue and its impact.
  • Steps to reproduce (minimal example or proof of concept).
  • Affected version(s) and platform.
  • Any suggested remediation, if you have one.

Response Timeline

  • Acknowledgement of your report within 7 days.
  • Initial triage and severity assessment within 14 days.
  • Coordinated disclosure target: 90 days from acknowledgement, or sooner if a fix can be shipped quickly. If an issue requires longer, we will discuss a revised timeline with you.

Supported Versions

Descry is pre-1.0. Only the latest minor release on PyPI receives security fixes. Users on older versions are encouraged to upgrade.

Credits

Researchers who report verified vulnerabilities are credited in the release notes unless they request anonymity.

There aren't any published security advisories