We provide security updates and patches for the following versions of ShinyShell:
| Version | Supported |
|---|---|
| 0.7.x | β |
| < 0.7.0 | β |
The ShinyShell team takes security issues seriously. Because ShinyShell is a zero-dependency library using exclusively the Python standard library, its attack surface is minimal. However, if you discover a security vulnerability or unexpected behavior involving input handling or terminal escape sequences:
- Do not report security vulnerabilities via public GitHub issues.
- Please report the issue via GitHub's Private Vulnerability Reporting or email the maintainer directly at hello@adnanahamedhimal.com.
- Include detailed steps to reproduce the vulnerability, sample code, and the affected Python/OS versions.
- We will acknowledge receipt of your vulnerability report within 48 hours.
- We will provide an estimated timeline for a fix.
- We will credit you in the release notes once the patch is published (if you desire).
Thank you for keeping ShinyShell and the Python open-source ecosystem safe!