If you believe you have found a security vulnerability in Parcel, please do not open a public issue. Instead, report it privately via GitHub's private vulnerability reporting form.
You can expect:
- An acknowledgement within a reasonable time (this is a personal, best-effort project — there is no SLA).
- A coordinated disclosure timeline once the issue is triaged.
Only the latest released version of Parcel receives fixes. Older versions are not patched.
In scope:
- The Home Assistant custom integration code under
custom_components/parcel/. - The Lovelace cards under
custom_components/parcel/frontend/.
Out of scope:
- Vulnerabilities in Home Assistant itself — please report those to the Home Assistant project.
- Vulnerabilities in carrier provider integrations (PostNL, DHL, …) that push data into Parcel — report those to their respective maintainers.
- Misconfiguration of a user's own Home Assistant instance.