| Version | Supported |
|---|---|
| 1.x | Yes |
If you discover a security vulnerability in behave-retry, please report it responsibly.
Do not open a public GitHub issue for security vulnerabilities.
Instead, email security@mathiaspaulenko.com with:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
You will receive a response within 72 hours. If the vulnerability is confirmed, a fix will be prepared and a security advisory will be published.
- You report the vulnerability privately.
- We acknowledge receipt within 72 hours.
- We investigate and confirm the issue.
- A fix is prepared and released.
- A GitHub Security Advisory is published with credit to the reporter (unless anonymity is requested).
This policy applies to the behave-retry package and its source code
hosted at MathiasPaulenko/behave-retry.
- Always pin the package version in your
requirements.txtorpyproject.toml. - Review dependencies regularly with
pip-auditor similar tools. - Report any suspicious behavior immediately.