Report vulnerabilities privately via one of:
- GitHub Security Advisories (preferred)
- Email: team@pycal.org
Please do not open public issues for security reports.
We ask that you delay public disclosure for at least 90 days after reporting, to give us time to coordinate a fix.
Security fixes are only applied to the latest release. Upgrade to the latest version to receive security updates.
After a report is verified and fixed:
- We publish a GitHub Security Advisory, which is submitted to the CVE List and the GitHub Advisory Database.
- We release a bug-fix version.
- We announce the fix in the change log and GitHub release notes.
- We credit the reporter in the advisory (unless they prefer to remain anonymous).