| Version | Supported |
|---|---|
| 0.3.x | ✅ |
| 0.2.x | ✅ |
| < 0.2 | ❌ |
If you discover a security vulnerability, please report it responsibly:
- DO NOT open a public issue
- Email security concerns to the maintainer
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
We will acknowledge receipt within 48 hours and provide a detailed response within 7 days.
main/masterbranches are protected- Force pushes and deletions are blocked
- All changes require Pull Request review
- Status checks must pass before merge
- All PRs run automated security scans
- Dependencies checked with
pip-audit - Code scanned with
bandit - No secrets in repository (
.envfiles gitignored)
- Dependabot enabled for automatic security updates
- Regular dependency audits
- Pinned versions for reproducibility
- Never commit secrets, API keys, or credentials
- Use environment variables for sensitive configuration
- Keep dependencies updated
- Follow secure coding guidelines
- Report suspicious activity immediately
We appreciate responsible disclosure from security researchers.