PyMotionLab is currently pre-1.0 and under active development. Security fixes will target the latest released version on PyPI once publishing begins.
| Version | Supported |
|---|---|
| main / unreleased | ✅ |
| < 0.1 | ❌ |
If you discover a security vulnerability in PyMotionLab (for example, unsafe deserialization of config files, arbitrary code execution via loaded arm specs, or a dependency with a known CVE):
- Do not open a public GitHub issue.
- Report it privately via GitHub's "Report a vulnerability" feature (Security tab on the repository), or by emailing the maintainer directly (see repository profile for contact info).
- Include: a description of the vulnerability, steps to reproduce, and the potential impact.
You should expect an initial response within 5 business days. Since this is a small, actively-developed project maintained largely by one person, timelines may vary — but reports will not be ignored.
Once a reported vulnerability is confirmed:
- A fix is developed and tested privately.
- A new version is released with the fix.
- The vulnerability is disclosed publicly (with credit to the reporter, unless they prefer to remain anonymous) after the fix is available.
This policy covers the PyMotionLab Python package itself. It does not cover vulnerabilities in third-party dependencies (report those upstream) or in example/demo code outside the core library.