Skip to content

Security: david-lev/pywa

SECURITY.md

Security Policy

Supported Versions

Currently, only the 4.x release line is supported with security updates.

Versions prior to 4.0 are no longer supported due to the BSUID changes that introduced breaking changes to the older codebase. We strongly encourage all users to upgrade to the latest 4.x release.

Version Supported
4.x.x
< 4.0.0

Reporting a Vulnerability

We take the security of pywa seriously. If you discover a security vulnerability, please do not disclose it publicly.

How to report: Please use GitHub's Private Vulnerability Reporting feature to ensure the issue remains confidential until a fix is released.

  1. Go to the Security tab of this repository and click Report a vulnerability.
  2. Provide a clear description of the issue and steps to reproduce it.

Alternatively, you can email reports directly to david@davidlev.dev.

What to expect:

  • You will receive an acknowledgment of your report within 48 hours.
  • We will use the private advisory to communicate, verify the issue, and work on a patch.
  • Once the vulnerability is patched and published, you will be credited for the discovery.

Please avoid opening public GitHub issues for sensitive security matters.

There aren't any published security advisories