cnbs-predictor is an actively developed research tool. Security fixes are applied to the latest released version only. If you are running an older release, please upgrade to the most recent version before reporting an issue.
| Version | Supported |
|---|---|
| 1.2.x | ✅ |
| < 1.2 | ❌ |
Please do not report security vulnerabilities through public GitHub issues, as that discloses the problem before it can be fixed.
Instead, report it privately through GitHub's built-in private vulnerability reporting:
- Go to the repository's Security tab.
- Click Report a vulnerability.
- Fill in the details of the issue.
This keeps the report confidential between you and the maintainers (@lefitzpatrick and @danijonesocean) until a fix is available.
- Acknowledgement: we aim to acknowledge a report as soon as possible, but we make no formal commitments.
- Updates: we will keep you informed as we investigate and work on a fix.
- Resolution: if the report is accepted, we will work on a fix and credit you (if you wish) when it is released. If it is declined, we will explain why.
Because this is a small research project maintained alongside other work, response times may vary. Thank you for helping keep cnbs-predictor and its users safe.