Skip to content

Security: predict-ably/call-report

SECURITY.md

Security Policy

Supported versions

call-report is pre-1.0 and under active development. Security fixes are applied to the latest released version only; there is no backporting to older releases at this time.

Reporting a vulnerability

Please report security vulnerabilities privately — do not open a public GitHub issue for them.

Please include enough detail to reproduce the issue. We aim to acknowledge reports within a few business days, and will keep you informed as we work on a fix and coordinate a release.

Scope

As a data-processing library, call-report follows the usual analytics trust model: data sources are assumed to be trusted, but the data itself may be malformed. We are most interested in issues where parsing untrusted or malformed call report files could lead to arbitrary code execution or unintended data exfiltration.

There aren't any published security advisories