Skip to content

Security: LanNguyenSi/scaffoldkit

Security

SECURITY.md

Security Policy

Supported Versions

Active development is on master. Once published to PyPI, only the latest release will be supported; until then, master is the supported state.

scaffoldkit generates project skeletons from declarative blueprints; vulnerabilities (path traversal in templates, code injection via blueprint content, supply-chain risk in generated dependencies) are treated as serious.

Reporting a Vulnerability

Please do not open a public GitHub issue for security reports.

Email contact@lan-nguyen-si.de with:

  • Affected version
  • Reproduction steps or proof-of-concept
  • Impact assessment

You will get an acknowledgement within 72 hours and an initial assessment within 7 days. A fix timeline depends on severity and complexity, communicated in the assessment.

There aren't any published security advisories