This policy covers the tollkeeper library and the airflow-tollkeeper package in this repository.
Do not open a public GitHub issue for security vulnerabilities.
Report privately using one of these channels:
- GitHub's private security advisory feature: go to the Security tab on this repository, then "Report a vulnerability".
- Email: sage.quotient@gmail.com
Include enough detail to reproduce the issue: affected version, a minimal repro, and the impact you expect.
You will get a response within 72 hours.
This project is pre-1.0. Fixes land on develop and ship in the next release; there is no separate maintenance branch.