Warning
Please do not file public GitHub issues for security vulnerabilities as they are open for everyone to see!
We encourage responsible disclosure practices for security vulnerabilities.
If you believe you've found a security-related bug, fill out a new vulnerability report via GitHub directly. To do so, follow these instructions:
- Click on the
Securitytab in the project repository. - Click the green
Report a vulnerabilitybutton at the top right corner. - Fill in the form as accurately as you can, including as many details as possible.
- Click the green
Submit reportbutton at the bottom.
Alternatively, drop an email to the maintainer's tox-plugins security mailbox instead of filing a ticket or posting to any public groups. Reports will be triaged in a timely manner and disclosed in a responsible way.
- Threat model -- the asset inventory, trust boundaries and mitigations the maintainer has assessed.
- Incident response playbook -- how the maintainer triages, fixes and discloses confirmed vulnerabilities.