This repository contains the Pyxle benchmark suite — reproducible load tests and the apps under test. It is not a published package, but we still want private disclosure for anything sensitive.
Please do not open a public issue for security reports.
Report privately through either channel:
- GitHub private advisory (preferred): Report a vulnerability
- Email: security@pyxle.dev
You will get an acknowledgement within 72 hours.
- Issues in the benchmark harness or fixtures that could execute untrusted code on a machine running the suite are in scope.
- A framework vulnerability surfaced by the benchmarks belongs in that
framework's repository — please report it against
pyxleinstead. - The published numbers are meant to be honest and reproducible; if you can reproduce a materially different result, please open a regular issue with your methodology — that's a correctness report, not a security one.