| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
If you discover a security vulnerability in django-rls-tenants, please report it responsibly. Do not open a public issue.
-
GitHub Private Advisory (preferred): Open a private security advisory on this repository.
-
Email: Send a detailed report to the maintainer listed in
pyproject.toml.
- A description of the vulnerability and its potential impact.
- Steps to reproduce the issue or a proof-of-concept.
- The version(s) affected.
- Any suggested fix, if you have one.
- Acknowledgement within 48 hours.
- Status update within 7 days with an assessment and remediation timeline.
- Fix release as soon as practical, typically within 30 days for confirmed vulnerabilities. A CVE will be requested when appropriate.
- Credit in the release notes (unless you prefer to remain anonymous).
This policy covers the django-rls-tenants Python package. Security concerns
related to PostgreSQL itself, Django, or other dependencies should be reported to
their respective maintainers.
For details on the library's security design, threat model, and guarantees, see the Security Model documentation.