Skip to content

Security: alpha-service/peppol-billing

Security

SECURITY.md

Security Policy

Reporting a vulnerability

If you discover a security issue (e.g. an XML injection vector in generated UBL, or a parser crash on malformed input), please do not open a public issue.

Instead, use GitHub's private vulnerability reporting or email the maintainer. We aim to acknowledge reports within 72 hours.

Scope

This library generates and parses UBL XML. Relevant concerns include:

  • XML escaping of all text/attribute content (all user-supplied values are escaped).
  • Safe parsing of untrusted inbound UBL (no entity expansion, no external fetch).

It does not transmit documents over the Peppol network and holds no credentials.

Supported versions

The latest published 0.x release receives security fixes.

There aren't any published security advisories