Skip to content

Latest commit

 

History

History
20 lines (14 loc) · 1.14 KB

File metadata and controls

20 lines (14 loc) · 1.14 KB

Security Policy — PyDevices Organization

Reporting Vulnerabilities

If you discover a security vulnerability within any repository under the PyDevices organization, please report it responsibly rather than opening a public issue.

Private vulnerability reporting is enabled on every active repository in the organization.

Disclosure Process

  1. Open a Private Vulnerability Report: go to the affected repository on GitHub, click the Security tab, then Report a vulnerability. This opens a private advisory visible only to you and the repo maintainers — no public issue, no email address needed.
  2. Include steps to reproduce, affected version(s), and potential impact.
  3. Maintainers will acknowledge your report within 48 hours and work with you on a patch release.

If a repository doesn't show a Report a vulnerability button (for example, a private or otherwise non-standard repo where GitHub doesn't offer the feature), open a regular issue labeled security with no reproduction details — just a note that you have something to report — and a maintainer will follow up privately for the rest.