Skip to content

Security: pyxle-dev/benchmarks

Security

SECURITY.md

Security Policy

This repository contains the Pyxle benchmark suite — reproducible load tests and the apps under test. It is not a published package, but we still want private disclosure for anything sensitive.

Reporting a vulnerability

Please do not open a public issue for security reports.

Report privately through either channel:

You will get an acknowledgement within 72 hours.

Scope

  • Issues in the benchmark harness or fixtures that could execute untrusted code on a machine running the suite are in scope.
  • A framework vulnerability surfaced by the benchmarks belongs in that framework's repository — please report it against pyxle instead.
  • The published numbers are meant to be honest and reproducible; if you can reproduce a materially different result, please open a regular issue with your methodology — that's a correctness report, not a security one.

There aren't any published security advisories