| Version | Supported |
|---|---|
| 0.x | ✅ |
We take security seriously. If you discover a vulnerability in pharma-vigilance, please report it responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
Instead, please email: security@pharma-vigilance.dev
Include the following in your report:
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact
- Suggested fix (if any)
- Acknowledgement within 48 hours
- Status update within 7 days with an initial assessment
- Resolution timeline communicated once the issue is confirmed
- Credit in the security advisory (unless you prefer to remain anonymous)
The following are in scope for security reports:
- Code execution: Arbitrary code execution through spider inputs or configuration
- Data exfiltration: Unintended data leakage through spiders or API endpoints
- Credential exposure: Hardcoded secrets, tokens, or API keys in the codebase
- Dependency vulnerabilities: Critical CVEs in direct dependencies
- Injection attacks: SQL injection, command injection, or path traversal
The following are out of scope:
- Vulnerabilities in third-party websites being scraped
- Denial-of-service against the scraping targets
- Issues requiring physical access to the host machine
We kindly ask that you:
- Allow reasonable time for us to address the issue before public disclosure
- Make a good-faith effort to avoid privacy violations and data destruction
- Do not access or modify data belonging to other users
- Keep pharma-vigilance updated to the latest version
- Store API keys and credentials in environment variables, never in code
- Run spiders with minimal required permissions
- Review spider configurations before deploying to production