You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi @quasar098 thanks for filing this ticket! Couple of things:
I merged a PR that updates our security policy to include 0.x versions. As chris mentioned, please go ahead and submit vulnerabilities as directed in SECURITY.md
The library version in pyproject.toml gets overwritten when we publish as a tagged version. This is an easy deployment process for us, but I'm in agreement that it can make it difficult to know the current version by viewing main branch. We're working on a solution to update this in an automated way.
We just cut release v0.4.0 today so that is the current version that has been published to pypi.
Part of that release included two (one, two) security patches from picklescan. Is this what you had in mind for your disclosure or is it something else?
I originally wanted to disclose a vulnerability, but am lost.
The
./pyproject.toml
states modelscan is at version 0.0.0, and the latest release is 0.3.0.Both of these are not applicable to the security policy, it seems (they are not conforming to
1.X
)Are vulnerabilities to be reported currently, or maybe not?
The text was updated successfully, but these errors were encountered: