Reporting of security issues in any project under github.com/propensive is welcome, encouraged and appreciated. The maintainers are grateful for responsible disclosure of vulnerabilities relating to the latest release and will work with you to resolve them quickly.
If you believe you’ve found a security vulnerability, please email the maintainers directly at:
When reporting, please include:
- a description of the issue, in particular, what behaviour you observed and how it did not meet your expectations;
- steps to reproduce the problem, preferably with a minimized example;
- and preferably, the tagged version or commit hash where the issue was found.
After receiving your report, the maintainers will:
- acknowledge receipt privately as soon as reasonably possible, usually within 72 hours;
- evaluate the issue to confirm its validity;
- work on a fix or mitigation;
- coordinate a release including the fix, usually the next release;
- thank you publicly (unless otherwise requested) once the issue is resolved.
Please do not publicly disclose the vulnerability until a fix has been released. If the issue is particularly severe, additional time may be requested for a coordinated release.
If you do not receive a timely response, you can make contact via other means, such as X or Discord.