Skip to content

Security: charliebarmore/ledgerpdf

SECURITY.md

Security policy

Reporting a vulnerability

Please use GitHub's Report a vulnerability private-reporting form for this repository. Do not open a public issue for a suspected security defect.

Do not attach a real client PDF, binder, screenshot, filename, tax identifier, or extracted page text. Reproduce with the synthetic fixtures when possible. If document structure matters, describe it without sending the document.

Include the LedgerPDF version, operating system, reproduction steps, expected impact, and whether the issue requires a specially crafted document. The maintainer will acknowledge a report within five business days and coordinate a fix and disclosure timeline based on severity.

Supported versions

Until the first stable release, only the newest published release receives security updates. LedgerPDF is currently alpha software and must not be the only copy of an engagement record.

There aren't any published security advisories