mloda is pre-1.0 and ships frequently. Security fixes are applied to the
latest released version on PyPI and the
main branch. We do not backport fixes to older releases. Please upgrade to
the latest version before reporting.
| Version | Supported |
|---|---|
| Latest release | ✅ |
| Older releases | ❌ |
Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions. This keeps users protected while a fix is prepared.
Instead, use one of these private channels:
- GitHub Private Vulnerability Reporting (preferred): Open the Security tab and click Report a vulnerability. This keeps the report, discussion, and coordinated disclosure in one place.
- Email: Write to security@mloda.ai.
Please include as much of the following as you can:
- The type of issue (e.g. injection, path traversal, deserialization, dependency vulnerability).
- The affected version, module, or file path (
file.py:lineif known). - Step-by-step reproduction or a proof of concept.
- The potential impact and any suggested mitigation.
- We'll get in touch to acknowledge your report.
- We'll assess the severity and keep you updated as we work toward a fix.
- We're happy to credit you in the advisory once it's published, unless you prefer to remain anonymous.
We follow coordinated disclosure: we ask that you give us a reasonable window to release a fix before any public disclosure. Thank you for helping keep mloda and its users safe.