Skip to content

Security: diwakergupta/whoosh

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.1.x

Reporting a Vulnerability

If you discover a security vulnerability in whoosh, please report it through GitHub Security Advisories.

Please do not open a public issue for security vulnerabilities.

What qualifies as a security issue

  • OAuth token or credential leakage
  • Unauthorized access to stored health data
  • SQL injection or other injection attacks
  • Insecure storage of sensitive data

What to include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response timeline

  • Acknowledgment within 48 hours
  • Status update within 7 days
  • Fix or mitigation plan within 30 days for confirmed vulnerabilities

There aren't any published security advisories