Skip to content

Security: nsollazzo/pecunia

Security

SECURITY.md

Security policy

Reporting a vulnerability

Please report security issues privately via GitHub Security Advisories:

https://github.com/nsollazzo/pecunia/security/advisories/new

Do not open a public issue or pull request for a security problem.

We will:

  1. Acknowledge receipt within 72 hours.
  2. Triage and assign a severity within 7 days.
  3. Release a fix on the soonest reasonable cadence, credit you in the release notes unless you ask otherwise, and publish a GHSA.

Supported versions

Pecunia is in early alpha (0.x). Only the latest published release on PyPI receives security fixes.

Scope

In scope:

  • The pecunia Python package on PyPI.
  • The GitHub Actions workflows in this repository.

Out of scope (please report upstream):

  • Vulnerabilities in uv, ruff, ty, pyright, cyclopts, polars, pydantic, or other third-party dependencies.

There aren't any published security advisories