Skip to content

Security: NeuroDevCo/pymbrola

.github/SECURITY.md

Security Policy

Thank you for helping keep pymbrola secure.

We take security reports seriously and appreciate responsible disclosure. If you believe you have found a vulnerability in this project, please report it privately and do not disclose it publicly until we have had a chance to investigate and address it.

Supported Versions

We provide security updates for:

  • the latest released version of pymbrola
  • the current default branch (main)

Older versions may receive limited support only if they are still actively maintained. If a version is not listed above, it should be considered unsupported for security fixes unless otherwise stated.

Reporting a Vulnerability

Please report vulnerabilities through one of the following methods:

  1. Preferred: GitHub Security Advisories

    • Go to the repository's Security tab
    • Click "Report a vulnerability"
    • Provide a detailed description of the issue and the impact
  2. If private reporting is not available:

    • Email the maintainers at: gongarciacastro@gmail.com
    • Include:
      • a description of the vulnerability
      • affected version(s) or commit hash
      • steps to reproduce the issue
      • the potential impact
      • any proof-of-concept or exploit details
      • suggested remediation, if available

Please do not open a public GitHub issue for security vulnerabilities.

What to Expect

We will do our best to acknowledge receipt of your report within 5 business days. We will then work with you to confirm the issue, assess the risk, and coordinate a fix and disclosure timeline.

We ask that reporters keep the issue confidential while we investigate and remediate it.

Disclosure Policy

We prefer to coordinate disclosure with the reporter. Once a fix is available, we may publish a security advisory or release notes describing the issue and the remediation.

If a vulnerability is found in a dependency or external system, we may coordinate with the relevant upstream project as needed.

Scope

This policy applies to the pymbrola project and its maintained codebase. It does not cover unrelated services, infrastructure, or third-party dependencies outside the project’s control unless they are explicitly part of the pymbrola distribution.

Thank you for helping us improve the security of pymbrola.

There aren't any published security advisories