Security fixes are prioritized for the latest published release on PyPI and the
current master tip. Older minor versions may not receive backports.
| Version | Supported |
|---|---|
| 2.3.x (latest tip / PyPI) | Yes |
| < 2.3 | No |
Please do not open a public GitHub issue for security-sensitive reports.
Prefer one of:
- GitHub Security Advisories for this repository (private disclosure), or
- Email the maintainer at travis.j.kessler@gmail.com with a description, impact, and reproduction steps if available.
You should receive an acknowledgment within a reasonable time. We will coordinate a fix and disclosure timeline with you when appropriate.
PyPI releases use trusted publishing (OIDC) via the
Publish GraphChem to PyPI GitHub Actions workflow on published GitHub
Releases. No long-lived PyPI API tokens are stored in this repository.
Maintainers must configure a GitHub Environment named pypi and a matching
PyPI trusted publisher for project graphchem.