Pourdown is under active development; only the latest release is supported with security fixes.
Please do not open a public GitHub issue for security vulnerabilities.
Instead, report it privately using one of these channels:
- GitHub Security Advisories for this repository (preferred — keeps the report private until a fix ships), or
- Email poo9810@gmail.com with details and, if possible, steps to reproduce.
Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce (a minimal sample file is especially helpful for import/parsing issues, since Pourdown's attack surface is largely untrusted document parsing — docx/xlsx/pptx/pdf)
- Your OS and Pourdown version
We'll acknowledge reports as soon as we can and keep you updated as a fix is developed. Please give us a reasonable amount of time to address the issue before any public disclosure.