Skip to content

Security: PyDevices/lvgl-python

SECURITY.md

Security Policy — PyDevices Organization

Reporting Vulnerabilities

If you discover a security vulnerability within any repository under the PyDevices organization, please report it responsibly rather than opening a public issue.

Private vulnerability reporting is enabled on every active repository in the organization.

Disclosure Process

  1. Open a Private Vulnerability Report: go to the affected repository on GitHub, click the Security tab, then Report a vulnerability. This opens a private advisory visible only to you and the repo maintainers — no public issue, no email address needed.
  2. Include steps to reproduce, affected version(s), and potential impact.
  3. Maintainers will acknowledge your report within 48 hours and work with you on a patch release.

If a repository doesn't show a Report a vulnerability button (for example, a private or otherwise non-standard repo where GitHub doesn't offer the feature), open a regular issue labeled security with no reproduction details — just a note that you have something to report — and a maintainer will follow up privately for the rest.

There aren't any published security advisories