Skip to content

Security: AgToffee/pharma-vigilance

Security

.github/SECURITY.md

Security Policy

Supported Versions

Version Supported
0.x ✅

Reporting a Vulnerability

We take security seriously. If you discover a vulnerability in pharma-vigilance, please report it responsibly.

How to Report

Do NOT open a public GitHub issue for security vulnerabilities.

Instead, please email: security@pharma-vigilance.dev

Include the following in your report:

  • Description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact
  • Suggested fix (if any)

What to Expect

  • Acknowledgement within 48 hours
  • Status update within 7 days with an initial assessment
  • Resolution timeline communicated once the issue is confirmed
  • Credit in the security advisory (unless you prefer to remain anonymous)

Scope

The following are in scope for security reports:

  • Code execution: Arbitrary code execution through spider inputs or configuration
  • Data exfiltration: Unintended data leakage through spiders or API endpoints
  • Credential exposure: Hardcoded secrets, tokens, or API keys in the codebase
  • Dependency vulnerabilities: Critical CVEs in direct dependencies
  • Injection attacks: SQL injection, command injection, or path traversal

The following are out of scope:

  • Vulnerabilities in third-party websites being scraped
  • Denial-of-service against the scraping targets
  • Issues requiring physical access to the host machine

Responsible Disclosure

We kindly ask that you:

  1. Allow reasonable time for us to address the issue before public disclosure
  2. Make a good-faith effort to avoid privacy violations and data destruction
  3. Do not access or modify data belonging to other users

Security Best Practices for Users

  • Keep pharma-vigilance updated to the latest version
  • Store API keys and credentials in environment variables, never in code
  • Run spiders with minimal required permissions
  • Review spider configurations before deploying to production

There aren't any published security advisories