If you believe you've found a security vulnerability in one of our projects, please report it privately rather than opening a public issue — this gives us a chance to investigate and release a fix before the details are public.
Please email security@pysmo.org with:
- A description of the vulnerability and its potential impact
- Steps to reproduce it, including any proof-of-concept code
- The affected version(s), if known
We'll acknowledge your report as soon as we can, and keep you updated as we investigate and work on a fix. Once a fix is available, we'll coordinate with you on disclosure timing and credit, if you'd like it.
Security fixes are targeted at the most recently released version of each project. Older versions are generally not backported.
This policy covers the code in repositories under the pysmo GitHub organisation. Vulnerabilities in third-party dependencies should be reported to their respective maintainers, though we're happy to hear about them too if they affect us directly.