FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Overview · facelessuser/pymdown-extensions · GitHub

Security: facelessuser/pymdown-extensions

SECURITY.md

Security Vulnerabilities

Our policy for security related issues is to fix related issues within our power on the most recent major release.

Versioning

Versioning follows PEP440: major.minior.patch.

Versions Description
Major This reserved for releases that introduce breaking features.
Minor This reserved for releases that introduce new functionality.
Patch This is reserved for releases that only include bug fixes.

Example

8.0
8.1
8.1.3

Create Security Vulnerability Report

If you have found a security vulnerability, you can create a draft "security advisory" on the GitHub repository, instructions here. Such advisories are kept private as the issue is explored.

Security Vulnerability Workflow

We will strive to acknowledge the report in about two business days.

Reports will be kept private until the issue is properly understood.

If the report is accepted we will notify Tidelift (who we've partnered with), request a CVE from GitHub, and work with the reporter to find a resolution. Work will be done privately.

The fix, announcement, and release will be negotiated with the reporter.

Afterwards, a release will be made and the vulnerability will be made public as close to each other as possible.

Security Notes

Performance related issues will be taken into considerations, but these extensions are also subject to any existing performance limitations of Python Markdown, which this project is simply a collection of extensions for. Any performance filings should take into consideration where the root of the problem actually resides.

Learn more about advisories related to facelessuser/pymdown-extensions in the GitHub Advisory Database

Back | FazBrowse Home | New Git URL