Skip to content

Security: wickedbyte/int-to-uuid-py

Security

SECURITY.md

Security Policy

Supported Versions

The following versions of this project are currently receiving security updates:

Version Supported
1.x.x

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussion threads.

Instead, use one of the following private channels:

We aim to acknowledge receipt of your report within 2 business days and will keep you informed as the issue is triaged and resolved.

What to Include

  • A clear description of the vulnerability and its potential impact
  • The affected version(s) and component(s)
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept code or a working exploit (if available)
  • Any suggested mitigations or patches you have in mind

Our Disclosure Process

Once a report is received, we follow a coordinated disclosure process:

  1. Acknowledgment — We confirm receipt within 2 business days and open a private channel with the reporter.

  2. Triage — We reproduce the issue, assess its severity using CVSS, and assign an internal priority.

  3. Remediation — We develop and test a fix. The timeline will vary with severity:

    Severity Target patch timeline
    Critical 7 days
    High 14 days
    Medium 30 days
    Low 60 days
  4. Notification — Before public release, we share the draft advisory and fix with you for review.

  5. Release & Advisory — The patched version is published and a security advisory is posted.


Safe Harbor

We appreciate the work of security researchers acting in good faith. If you report responsibly and do not exploit the issue beyond demonstration, we will not pursue legal action.


Preferred Languages

We prefer to receive reports in English.


This policy is maintained by WickedByte and applies to all open source projects published under this organization.

There aren't any published security advisories