We actively support and patch security vulnerabilities in the following versions of Calibra:
| Version | Supported |
|---|---|
| Latest | ✅ Yes |
| < Latest | ❌ No |
We recommend always running the latest version available on PyPI (calibra-robotics).
If you discover a security vulnerability in Calibra, please do not open a public GitHub issue. Instead, report it responsibly by taking the following steps:
- Email us: Send a detailed email description to the repository maintainer (or the email listed on the author profile).
- Include details: Provide steps to reproduce, a proof of concept (PoC), and potential impacts.
- Wait for response: We will acknowledge your report within 48 hours and work on a security patch.
- Coordinated Disclosure: We ask that you give us a reasonable timeframe (typically 30–90 days) to deploy a fix before disclosing it publicly.