Skip to content

Security: SupRaKoshti/FastAPI-Therapist

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest published release of fastapi-therapist on PyPI is supported with security fixes.

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Instead, report it privately by emailing koshtisahil02@gmail.com with:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce (a minimal FastAPI project or code snippet, if relevant)
  • Any suggested fix, if you have one

You should expect an initial response within a few days. Once the issue is confirmed, a fix will be prepared and a new release published; you'll be credited in the release notes unless you prefer to stay anonymous.

Scope

fastapi-therapist is a static analysis tool that parses Python source with ast — it does not execute the code it scans. Relevant vulnerability classes include things like:

  • Path traversal or arbitrary file access when resolving config/ignore files
  • ReDoS or crashes triggered by malicious source files being scanned
  • Supply-chain issues in the published package itself

It generally does not include false positives/negatives in individual lint rules — please file those as regular bug reports instead.

There aren't any published security advisories