This repository accepts security reports for:
- Python package runtime and indexing/search surfaces (
code/zpe_geo). - Repo-local scripts, fixtures, and packaging metadata that affect published behavior (
code/scripts,code/fixtures,pyproject.toml). - CI and release pipeline configurations.
Please report vulnerabilities privately to the project owner with:
- A clear impact summary.
- Reproduction steps or proof-of-concept.
- Affected versions/commit ranges.
- Suggested remediation when available.
- Initial acknowledgement: within 5 business days.
- Triage and severity classification: within 10 business days.
- Remediation timeline: shared after triage.
Public disclosure should be coordinated after a fix is available.