We take the security of this project seriously. We appreciate your efforts to responsibly disclose your findings and will make every effort to acknowledge your contributions.
Only the latest released version of tmodbus receives security updates. Older versions will not be patched; please upgrade to the latest release to receive fixes.
| Version | Supported |
|---|---|
| Latest release | ✅ |
| Older releases | ❌ |
Please do not report security vulnerabilities through public GitHub issues.
If you discover a security vulnerability, please report it privately using GitHub's private vulnerability reporting at https://github.com/wlcrs/tmodbus/security/advisories/new.
When reporting, please include:
- A description of the vulnerability and its potential impact.
- Steps to reproduce the issue or a proof of concept.
- The affected version(s) of this package.
- Any known mitigations or workarounds.
- Acknowledgement: we aim to acknowledge receipt of your report within 7 days.
- Initial assessment: we aim to provide an initial assessment within 14 days, including whether we consider the report to be a valid vulnerability.
- Fix and disclosure: we aim to ship a fix and publish the advisory within 90 days of the initial report. For severe issues we may move faster; for complex issues we may request a reasonable extension and keep you informed.
The following are explicitly not covered by this security policy:
- Vulnerabilities in unsupported (older) versions of this package. Please upgrade to the latest release first.
- Vulnerabilities in third-party dependencies. These are tracked and updated automatically via dependabot and should be reported upstream to the relevant project.
Thank you for helping keep this project secure!