The latest main branch and the latest published release are actively supported with security fixes.
If you discover a security issue, please report it privately:
- Open a private security advisory on GitHub for this repository, or
- Email the maintainer listed in the project profile.
Please include:
- A clear description of the issue
- Steps to reproduce
- Potential impact
- Suggested remediation (if available)
- We acknowledge reports within 72 hours.
- We validate and triage severity.
- We prepare and test a fix.
- We publish a patched release and disclose details responsibly.
This policy applies to:
- The
forecostPython package - CLI entrypoints and local database interactions
- Bundled GitHub Actions workflows