Skip to content

Security: fre-ms/qdaPy

Security

SECURITY.md

Security Policy

Supported versions

Only the latest release of qdaPy receives security fixes. If you are on an older version, update before reporting.

Reporting a vulnerability

Please report security problems privately by email to fre.ms@fre.ms. Do not open a public issue, pull request or discussion for a suspected vulnerability.

Include enough to reproduce the problem: what you did, what happened, the qdaPy version and your environment (Python version, operating system).

What to expect

  • A timely acknowledgement of your report.
  • An assessment and coordinated disclosure: a fix is prepared and released before the details are made public, and you are credited if you wish.

Data-handling and privacy concerns

qdaPy reads bibliographic records and qualitative-coding data from exported files. If something about how the package handles that data worries you — not only a classic vulnerability — a report to the same address is welcome.

There aren't any published security advisories