| Version | Supported |
|---|---|
| 0.1.x | ✅ |
If you discover a security vulnerability in ERDAlchemy, please report it responsibly.
Do not open a public GitHub issue for security vulnerabilities.
Instead, use GitHub's private vulnerability reporting to submit your report. Include:
- A description of the vulnerability
- Steps to reproduce the issue
- The potential impact
- Any suggested fix (optional)
You can expect an initial response within 72 hours. Once the issue is confirmed, a fix will be prioritized and released as a patch version. You will be credited in the release notes unless you prefer to remain anonymous.
ERDAlchemy is a visualization library that reads SQLAlchemy model metadata and produces SVG/PNG/PDF diagrams. It does not handle authentication, network requests, or user-supplied SQL. Security concerns most likely to be relevant include:
- SVG injection via crafted model metadata (table names, column names)
- Path traversal in file output paths
- Dependency vulnerabilities (SQLAlchemy, CairoSVG)
- Keep ERDAlchemy and its dependencies up to date.
- Avoid passing untrusted input as model metadata if generating diagrams in automated pipelines.