We take security vulnerabilities seriously. If you discover a security vulnerability in TaskQ, please report it responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
Instead, please use GitHub Security Advisories to report vulnerabilities privately.
- Acknowledgment: Within 48 hours
- Initial Assessment: Within 5 business days
- Fix or Mitigation: Depends on severity, typically within 30 days for high-severity issues
This policy covers the TaskQ Python package and its CI/CD pipeline. Vulnerabilities in third-party dependencies should be reported to their respective maintainers.
We follow coordinated disclosure. Once a fix is released, we will publish a GitHub Security Advisory with credit to the reporter (unless they prefer to remain anonymous).