Django Mindoff Security Policy
For an API-building framework, security stands above everything. Responsible disclosure about any vulnerability is truly appreciated 👏.
Only the latest version of the django-mindoff package is actively supported. So, it’ll be helpful if you can confirm the issue on the newest version first.
Reporting a Vulnerability¶
Email us at joe@mindoff.work. If you’re unsure whether something is a security issue, it’s still OK to reach out.
Include whatever you have, ideally:
- What you found and why it matters
- How to reproduce it (steps or a small proof‑of‑concept)
- Expected impact
- Environment or dependency details
Please do not open a public issue or discussion while we’re investigating as it's better for the community to work together and arrive a solution privately.
If it’s a confirmed vulnerability, You'll get the credit in the docs unless you’d prefer to stay low-key.
🙏 Thanks for helping keep django-mindoff safe.