Only the latest published release of fastapi-therapist on PyPI is supported
with security fixes.
Please do not open a public GitHub issue for security vulnerabilities.
Instead, report it privately by emailing koshtisahil02@gmail.com with:
- A description of the vulnerability and its potential impact
- Steps to reproduce (a minimal FastAPI project or code snippet, if relevant)
- Any suggested fix, if you have one
You should expect an initial response within a few days. Once the issue is confirmed, a fix will be prepared and a new release published; you'll be credited in the release notes unless you prefer to stay anonymous.
fastapi-therapist is a static analysis tool that parses Python source with
ast — it does not execute the code it scans. Relevant vulnerability classes
include things like:
- Path traversal or arbitrary file access when resolving config/ignore files
- ReDoS or crashes triggered by malicious source files being scanned
- Supply-chain issues in the published package itself
It generally does not include false positives/negatives in individual lint rules — please file those as regular bug reports instead.