Skip to content

Security: MishaKav/pytest-coverage-comment

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in pytest-coverage-comment, please report it privately to help keep the community safe.

How to Report

Please do not report security vulnerabilities through public GitHub issues.

Instead, please use one of these methods:

  1. GitHub Security Advisories (preferred):

    • Go to the Security tab
    • Click "Report a vulnerability"
    • Fill out the form with details
  2. Email: Contact the maintainer directly through GitHub profile

What to Include

  • Description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 1 week
  • Fix and disclosure: Coordinated with reporter

Supported Versions

We release security updates for the latest version. Please ensure you're using the most recent release.

Version Supported
Latest ✅
Older ❌

Security Best Practices

When using this action in your workflows:

  • Pin action versions to specific tags (e.g., @v1.2.3) rather than branches
  • Review action permissions in your workflow files
  • Keep dependencies up to date
  • Limit token permissions to the minimum required

Thank you for helping keep pytest-coverage-comment secure!

There aren't any published security advisories