Reporting a security issue
We take security very seriously and ask that you follow our security policy carefully.
Important! If you believe you've identified a security issue with Warehouse, DO NOT report the issue in any public forum, including (but not limited to):
- Our GitHub issue tracker
- Official or unofficial chat channels
- Official or unofficial mailing lists
Instead, please email Donald Stufft and/or Ernest W. Durbin III directly, providing as much relevant information as possible.
Messages may be optionally encrypted with GPG using key fingerprints (these public keys are available from most commonly-used key servers):
- Donald Stufft: firstname.lastname@example.org
7C6B 7C5D 5E2B 6356 A926 F04F 6E3C BCE9 3372 DCFA
- Ernest W. Durbin III: email@example.com
11CD 3DD9 8D7E 61C7 6D1A 3224 8815 9C24 830F 6F7E
What happens next?
Once you've submitted an issue via email, you should receive an acknowledgment within 48 hours.
Depending on the action to be taken, you may receive further follow-up emails.
This security policy was last updated on May 13, 2017