Security updates are provided for the latest releases:
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
If you discover a security vulnerability in pyxsdata-core (such as memory safety issues, buffer overflows, unbounded memory allocations, or XML entity vulnerabilities), please do NOT disclose it publicly.
Instead, report security issues via:
-
GitHub Security Advisories (Preferred):
- Visit the Security tab on GitHub and click "Report a vulnerability".
-
Email:
- Send an email to bailey.tan.nguyen@gmail.com with the subject line
[SECURITY] pyxsdata-core vulnerability report.
- Send an email to bailey.tan.nguyen@gmail.com with the subject line
- Detailed description of the vulnerability.
- Minimal XML payload and Python / Rust invocation demonstrating the problem.
- Impact assessment and any suggested fixes.
- Initial Response: Within 48 hours.
- Triage & Patching: Within 5 business days.
- Public advisories and patched wheel releases will be coordinated responsibly.