Thank you for helping keep pymbrola secure.
We take security reports seriously and appreciate responsible disclosure. If you believe you have found a vulnerability in this project, please report it privately and do not disclose it publicly until we have had a chance to investigate and address it.
We provide security updates for:
- the latest released version of pymbrola
- the current default branch (
main)
Older versions may receive limited support only if they are still actively maintained. If a version is not listed above, it should be considered unsupported for security fixes unless otherwise stated.
Please report vulnerabilities through one of the following methods:
-
Preferred: GitHub Security Advisories
- Go to the repository's Security tab
- Click "Report a vulnerability"
- Provide a detailed description of the issue and the impact
-
If private reporting is not available:
- Email the maintainers at: gongarciacastro@gmail.com
- Include:
- a description of the vulnerability
- affected version(s) or commit hash
- steps to reproduce the issue
- the potential impact
- any proof-of-concept or exploit details
- suggested remediation, if available
Please do not open a public GitHub issue for security vulnerabilities.
We will do our best to acknowledge receipt of your report within 5 business days. We will then work with you to confirm the issue, assess the risk, and coordinate a fix and disclosure timeline.
We ask that reporters keep the issue confidential while we investigate and remediate it.
We prefer to coordinate disclosure with the reporter. Once a fix is available, we may publish a security advisory or release notes describing the issue and the remediation.
If a vulnerability is found in a dependency or external system, we may coordinate with the relevant upstream project as needed.
This policy applies to the pymbrola project and its maintained codebase. It does not cover unrelated services, infrastructure, or third-party dependencies outside the project’s control unless they are explicitly part of the pymbrola distribution.
Thank you for helping us improve the security of pymbrola.