TurboPy is under active development. Security updates are provided for the latest version available in the repository and the most recent official release.
| Version | Supported |
|---|---|
| Latest release | ✅ |
Development branch (main) |
✅ |
| Older releases | ❌ |
If you discover a security vulnerability in TurboPy, please report it privately and responsibly.
- GitHub Security Advisory: Use GitHub's private vulnerability reporting feature when available.
- Repository: TurboPy
- Maintainer: @mihaimoga
Please provide as much information as possible:
- A description of the vulnerability
- Steps to reproduce the issue
- A proof-of-concept, if available
- The affected version or commit
- Potential impact
- Suggested remediation (optional)
After receiving a report, the maintainer will:
- Acknowledge receipt of the report.
- Investigate and validate the issue.
- Determine the severity and potential impact.
- Develop and test a fix when appropriate.
- Release the fix and publicly disclose details after remediation.
Security issues may include, but are not limited to:
- Arbitrary code execution
- Privilege escalation
- Unsafe handling of files or project data
- Insecure update mechanisms
- Vulnerabilities in bundled components or dependencies
- Denial-of-service conditions caused by malformed input
Please do not publicly disclose security vulnerabilities until a fix has been developed and released. Responsible disclosure helps protect all TurboPy users while remediation is underway.
TurboPy uses third-party libraries and components. Vulnerabilities originating in external dependencies should also be reported to the respective upstream projects when appropriate.
Security fixes will be documented in release notes and published through the project's GitHub releases.
Thank you for helping keep TurboPy and its users secure.