Security fixes are provided for the latest version of
fastapi-request-observability published on
PyPI. Older releases,
pre-1.0 releases, and unreleased commits are not supported. Upgrade to the
latest release before reporting a vulnerability when possible.
The supported Python and FastAPI versions are documented in the README. A problem caused solely by an unsupported Python or FastAPI version is outside this policy.
Do not open a public issue for a suspected vulnerability. Use GitHub private vulnerability reporting instead.
Include enough information to reproduce and assess the report:
- the affected
fastapi-request-observability, Python, FastAPI, and Starlette versions; - relevant middleware and logging configuration;
- a minimal reproduction or clear reproduction steps;
- the security impact, attack conditions, and affected data; and
- any known mitigation or proposed fix.
Use synthetic data. Do not include credentials, cookies, request or response bodies, private logs, or other secrets.
Please allow up to seven days for an initial response. Accepted reports will be handled privately while a fix and coordinated disclosure are prepared. If a report is declined, the response will explain why. Do not disclose the issue publicly before coordinated disclosure.
Report vulnerabilities that exist solely in Python, FastAPI, Starlette, HTTPX2, or another dependency to the affected upstream project. General bugs and hardening suggestions without a security impact belong in the public issue tracker.
This project does not currently offer a bug bounty.