If you discover a security vulnerability in this software, please report it responsibly. Do not open a public GitHub issue, pull request, or discussion, as this may put users at risk before a fix is available.
Instead, report it privately using GitHub private vulnerability reporting: open this repository's Security tab and click Report a vulnerability. Your report is visible only to you and to the repository's administrators and security managers.
If private vulnerability reporting is not available on this repository, report it through the ECMWF Support Portal instead, stating the affected repository.
In either case, please include where possible:
- a description of the vulnerability and its potential impact;
- the steps, configuration, or input needed to reproduce it;
- any known mitigations or workarounds.
We will acknowledge receipt within 5 business days and aim to provide an initial assessment within 10 business days. Please give us a reasonable opportunity to investigate and release a fix before any public disclosure.
Unless stated otherwise for a specific release, security updates are applied to the latest released version only. Users are encouraged to stay up to date with the latest release.
| Version | Supported |
|---|---|
| Latest | Yes |
| Older | No |
This policy applies to the code maintained in this repository. Vulnerabilities in third-party dependencies should be reported to their respective maintainers; where such a vulnerability also affects this project, please still let us know through the channel above so we can track and address the impact.