Skip to content

Security: raws-labs/srig-python

Security

SECURITY.md

Security Policy

We take the security of our software seriously and appreciate responsible disclosure of vulnerabilities.

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues or pull requests.

Instead, email contact@raws.at with:

  • the affected project and version (or commit),
  • a description of the vulnerability and its impact,
  • steps to reproduce, or a proof of concept, and
  • any suggested mitigation, if you have one.

Where a repository has GitHub private vulnerability reporting enabled, you may also use that repository's Security → Report a vulnerability form.

We will acknowledge your report as soon as we can and keep you informed as we investigate and work on a fix. Please give us a reasonable opportunity to address the issue before disclosing it publicly, and avoid accessing or modifying other people's data while researching.

Supported versions

Security fixes target the latest released version of each project. If you are running an older release, please update to the latest one before reporting, in case the issue is already resolved.

Scope

This policy covers the code in the raws-labs repositories. Vulnerabilities in third-party dependencies should be reported to their respective upstream projects; if such an issue affects one of ours, we're glad to hear about it too.

There aren't any published security advisories