Only the latest release of qdaPy receives security fixes. If you are on an older version, update before reporting.
Please report security problems privately by email to fre.ms@fre.ms. Do not open a public issue, pull request or discussion for a suspected vulnerability.
Include enough to reproduce the problem: what you did, what happened, the qdaPy version and your environment (Python version, operating system).
- A timely acknowledgement of your report.
- An assessment and coordinated disclosure: a fix is prepared and released before the details are made public, and you are credited if you wish.
qdaPy reads bibliographic records and qualitative-coding data from exported files. If something about how the package handles that data worries you — not only a classic vulnerability — a report to the same address is welcome.