If you discover a security vulnerability within any repository under the PyDevices organization, please report it responsibly rather than opening a public issue.
Private vulnerability reporting is enabled on every active repository in the organization.
- Open a Private Vulnerability Report: go to the affected repository on GitHub, click the Security tab, then Report a vulnerability. This opens a private advisory visible only to you and the repo maintainers — no public issue, no email address needed.
- Include steps to reproduce, affected version(s), and potential impact.
- Maintainers will acknowledge your report within 48 hours and work with you on a patch release.
If a repository doesn't show a Report a vulnerability button (for
example, a private or otherwise non-standard repo where GitHub doesn't offer
the feature), open a regular issue labeled security with no reproduction
details — just a note that you have something to report — and a maintainer
will follow up privately for the rest.