Active development is on master. Once published to PyPI, only the latest release will be supported; until then, master is the supported state.
scaffoldkit generates project skeletons from declarative blueprints; vulnerabilities (path traversal in templates, code injection via blueprint content, supply-chain risk in generated dependencies) are treated as serious.
Please do not open a public GitHub issue for security reports.
Email contact@lan-nguyen-si.de with:
- Affected version
- Reproduction steps or proof-of-concept
- Impact assessment
You will get an acknowledgement within 72 hours and an initial assessment within 7 days. A fix timeline depends on severity and complexity, communicated in the assessment.