Skip to content

Security: programmersd21/pyratatui

Security

SECURITY.md

Security Policy

πŸ”’ Supported Versions

We actively maintain and provide security updates for the following versions of this project:

Version Supported
Latest βœ…
Older versions ❌

If you are using an unsupported version, please upgrade to the latest release.


🚨 Reporting a Vulnerability

We take security issues seriously and appreciate responsible disclosure.

If you discover a vulnerability, please follow these steps:

  1. Do not open a public issue

  2. Report it privately via:

  3. Include the following details:

    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if available)

We will acknowledge receipt of your report within 48 hours.


πŸ› οΈ Response Process

Once a vulnerability is reported:

  1. We will investigate and validate the issue
  2. A fix will be developed and tested
  3. We may release a patch and/or new version
  4. The vulnerability may be disclosed publicly after a fix is available

⏱️ Disclosure Policy

  • We follow responsible disclosure
  • Please allow us reasonable time to fix the issue before public disclosure
  • We aim to resolve critical issues as quickly as possible

πŸ§ͺ Security Best Practices

To help keep this project secure:

  • Keep dependencies up to date
  • Avoid committing secrets or credentials
  • Use environment variables for sensitive data
  • Follow secure coding practices
  • Review code changes carefully before merging

πŸ” Supported Security Practices

This project may use:

  • Dependency scanning tools
  • Static code analysis
  • Automated security checks in CI/CD pipelines

⚠️ Scope

This security policy applies only to:

  • The core repository code
  • Official releases and distributions

It does not cover:

  • Third-party dependencies (report to respective maintainers)
  • Misconfigurations in user environments

πŸ™ Acknowledgements

We appreciate the efforts of security researchers and contributors who help improve the safety of this project.

(If desired, we may publicly acknowledge reporters who responsibly disclose vulnerabilities.)


πŸ“„ License

By reporting vulnerabilities or contributing fixes, you agree that your contributions will be licensed under the same license as this project.

There aren't any published security advisories