If you believe you have found a security vulnerability in any Pybara repository, please use GitHub's private vulnerability reporting on the affected repository, or email security@pybara.com. Do not open a public issue.
If reporting by email, please include:
- A description of the vulnerability
- Steps to reproduce it
- Your assessment of the impact
We aim to acknowledge reports within five business days and to resolve confirmed vulnerabilities as quickly as possible. We do not currently operate a paid bug bounty program.
Only the latest release of each project receives security updates.
In scope: code in Pybara repositories and the Pybara payment flow.
Out of scope: third-party platforms and dependencies (WordPress core, WooCommerce core, wallet providers, browser extensions), and the underlying Internet Computer infrastructure. Vulnerabilities in the Internet Computer itself should go to the DFINITY Foundation.
- Give us reasonable time to address the issue before public disclosure
- Do not access, modify or exfiltrate data beyond what is needed to demonstrate the vulnerability
- Comply with all applicable laws
English.