| Version | Supported |
|---|---|
| 0.1.x | Yes |
Only the latest release in the 0.1.x series receives security fixes.
Please do not open a public GitHub issue for security vulnerabilities.
Report vulnerabilities by email to itsonlyme@nigelcopley.com. Include:
- A description of the vulnerability and its potential impact.
- Steps to reproduce or a minimal proof-of-concept.
- The django-hostmap version you tested against.
- Any suggested remediation if you have one.
You will receive an acknowledgement within 3 business days. We aim to provide an initial assessment within 7 days of receipt.
django-hostmap follows coordinated disclosure with a 90-day embargo period:
- Vulnerability is reported privately to the maintainers.
- Maintainers assess severity and develop a fix.
- A patched release is published.
- A security advisory is issued at the same time as the release.
- If no fix is available after 90 days, the reporter may disclose publicly.
We will credit reporters in the advisory unless anonymity is requested.