Security fixes are only applied to the latest release on PyPI. 安全修复只针对 PyPI 上的最新发布版本。
| Version | Supported |
|---|---|
| latest release (see CHANGELOG.md) | ✅ |
| older releases | ❌ |
请勿在公开 issue 中报告安全漏洞。 Please do not report security vulnerabilities through public GitHub issues.
Preferred channels (任选其一,优先推荐第一种):
- GitHub Private Vulnerability Reporting(已启用): 仓库页 → Security → Report a vulnerability,全程私密。
- Email: zengzichao@sjtu.edu.cn,
邮件标题请注明
[PyiTOL security]。
We aim to acknowledge reports within 7 days and will keep you informed of the fix progress. Please include a description, reproduction steps, and the affected version / commit if possible.
我们会在 7 天内确认收到报告,并同步修复进展。报告时请尽量附上: 漏洞描述、复现步骤、受影响的版本或 commit。
Of particular interest:
- CLI/模板文件解析路径(Newick/Nexus/CSV 等不可信输入的处理);
- API client 的凭据处理(iTOL API key 的读取、存储与传输);
- 任何导致数据丢失、凭据泄露或向第三方服务器意外发送用户数据的行为。
Out of scope: issues in iTOL web service itself (report to iTOL maintainers).