Skip to content

Security: Johnkothapalli/python-code-health-analyzer

SECURITY.md

Security Policy

Supported Versions

The project is currently pre-1.0. Security fixes are applied to the latest release and the main branch; older releases may not receive backports.

Reporting A Vulnerability

Use GitHub's private vulnerability reporting from the repository's Security tab. Do not open a public issue containing an undisclosed vulnerability, exploit, credential, or sensitive source.

Include:

  • the affected version or commit;
  • a minimal reproduction using non-sensitive sample code;
  • the expected and observed behavior;
  • the likely impact; and
  • a suggested mitigation, if known.

The maintainer will acknowledge reports on a best-effort basis, investigate reproducible findings, and coordinate disclosure after a fix is available. This project does not offer a bug bounty.

Findings in code scanned by the analyzer are not vulnerabilities in this repository. Discuss false positives or missing detections through a normal issue unless disclosure would itself expose sensitive information.

There aren't any published security advisories