Carnopy is alpha software. Only the latest version published on PyPI receives security fixes. Older alpha versions are not supported or backported.
Do not report security vulnerabilities through a public GitHub issue.
Preferred reporting channel:
- Open the repository's Security tab.
- Select Report a vulnerability.
- Submit a private vulnerability report with reproduction details and affected versions.
If private vulnerability reporting is unavailable, email gc@carnopy.org.
Include:
- the affected Carnopy version;
- the installation and operating environment;
- a minimal reproduction or proof of concept;
- the expected impact;
- any known mitigations.
Please avoid accessing data or systems that you do not own and avoid publicly disclosing the issue before a fix can be evaluated.
Carnopy does not promise a response-time SLA, embargo duration, backport, or bounty. Reports will be assessed according to severity, reproducibility, and the current alpha scope.