Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Security: beartype/beartype

.github/SECURITY.md

we doin' this

Report a Vulnerability Today for a Future Tomorrow

Please report any security issue whatsoever in the @beartype ecosystem by privately submitting:

Our gratitude is infinite. Open-source software improves the mutual security of humanity through openness, transparency, and many eyeballs. You are those eyeballs.

We Secure Your Software So You Don't Have To

Despite the thrilling puns that even now bedevil our documentation, @beartype is a production-grade family of quality assurance (QA) devtooling leveraged by security-conscious governments, corporations, non-profits, and citizens the world over – including the United Kingdom's very own Government Communications Headquarters (GCHQ).

@beartype maintainers, developers, and users alike treat security concerns with the gravity they deserve. You care about security. So do we. Your concerns concern us. We humbly appreciate your efforts to responsibly disclose security vulnerabilities. In return, we will act swiftly to:

  1. Privately reply to your private disclosure with bald-faced panic. Just kidding! We'll inform you about what happens next. Some amount of panicking might be involved. Ideally, not much.
  2. Privately communicate with you during our resolution process. This is where the "fun" happens. We might request additional information, guidance, metadata, and spiritual support.
  3. Publicly publish a new stable release resolving these vulnerabilities.
  4. Publicly disclose the vulnerabilities you discovered, usually alongside a new Announcement announcing the aforementioned new stable release in the Discussion forums for this public GitHub repository. Our public disclosure will document this vulnerability in detail – including some or all of:
    • Which @beartype features are affected.
    • How @beartype users can strategically mitigate this vulnerability. The answer usually reduces to: "Update @beartype and pray for your safety!" We'll embellish this answer with animated memes that make the @beartype userbase superficially feel better about what actually is a deep tragedy.
    • How you personally discovered this vulnerability.
  5. Publicly acknowledge your invaluable personal contributions.

Our gratitude intensifies. Your eyeballs continue to make the world a safer place. Bet you didn't know your eyeballs could do that, huh? Yet they did. When humanity is secured, quality is assured.

There aren’t any published security advisories