Please report security issues privately via GitHub Security Advisories:
https://github.com/nsollazzo/pecunia/security/advisories/new
Do not open a public issue or pull request for a security problem.
We will:
- Acknowledge receipt within 72 hours.
- Triage and assign a severity within 7 days.
- Release a fix on the soonest reasonable cadence, credit you in the release notes unless you ask otherwise, and publish a GHSA.
Pecunia is in early alpha (0.x). Only the latest published release on
PyPI receives security fixes.
In scope:
- The
pecuniaPython package on PyPI. - The GitHub Actions workflows in this repository.
Out of scope (please report upstream):
- Vulnerabilities in
uv,ruff,ty,pyright,cyclopts,polars,pydantic, or other third-party dependencies.