Please do not report security vulnerabilities through public GitHub issues.
Instead, report them privately using GitHub's security advisory feature:
- Go to the Security tab of the repository.
- Select Advisories → Report a vulnerability.
- Fill in the advisory form and submit.
This opens a private draft advisory visible only to the maintainers, so the details stay confidential until a fix is ready.
To help us triage quickly, please include as much of the following as possible:
- The affected version (release tag, commit SHA, or "latest
main"), and whether you are running via Docker or a native install. - Step-by-step instructions to reproduce the issue.
- The expected impact / potential attack scenario (what an attacker could achieve).
- Any suggested mitigations, if you have them.
- We aim to acknowledge receipt within a few business days.
- We will investigate and keep you informed of progress toward a fix.
- We prefer to develop and release a fix before any public disclosure, and we are happy to coordinate a disclosure timeline with you and credit reporters who wish to be acknowledged.
Thank you for helping keep pspcz_analyzer and its users safe.