The security of this project is taken seriously. We appreciate your efforts to responsibly disclose any findings and will make every effort to acknowledge your contributions.
Security updates are provided only for the latest released version of this library on PyPI. Users are strongly encouraged to keep their installations up to date.
| Version | Supported |
|---|---|
| Latest release | ✅ |
| Older releases | ❌ |
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, report them privately through GitHub's private vulnerability reporting:
When reporting, please include as much of the following as possible:
- A clear description of the vulnerability and its potential impact.
- Steps to reproduce, or a proof of concept.
- Affected version(s) of the library.
- Any known mitigations or workarounds.
- Acknowledgement: you will receive an acknowledgement of your report within 48 hours.
- Initial assessment: a triage and initial severity assessment will be shared within 7 days of the acknowledgement.
- Fix and disclosure: valid reports are targeted for resolution and coordinated public disclosure within 90 days of the initial report, depending on complexity and impact.
You will be kept informed throughout the process and credited in the release notes for the fix, unless you prefer to remain anonymous.
The following are not considered security vulnerabilities in this project:
- Vulnerabilities in upstream or transitive dependencies. These are handled continuously by Renovate and addressed through regular dependency updates.
- Issues only reproducible on Python versions older than those listed as
supported in
pyproject.toml. - Issues in the Tuya cloud platform or device firmware itself; please report those directly to Tuya.
- Issues in Home Assistant itself; please report those through Home Assistant's security policy.
This security policy covers the tuya-device-handlers Python package
published on PyPI and its
source code in this repository.