This document outlines security policy and procedures for the CrowdStrike cs.aws_account
project.
- Supported Python versions
- Supported cs.aws_account versions
- Reporting a potential security vulnerability
- Disclosure and Mitigation Process
cs.aws_account supports the following versions of Python.
Version | Supported |
---|---|
3.12.x | |
3.11.x | |
3.10.x | |
3.9.x | |
3.8.x | |
<= 3.7.x | |
<= 2.x.x |
When discovered, we release security vulnerability patches for the most recent release at an accelerated cadence.
We have multiple avenues to receive security-related vulnerability reports.
Please report suspected security vulnerabilities by:
- Submitting a bug.
- Submitting a pull request to potentially resolve the issue. (New contributors: please review the content located here.)
- Sending an email to [email protected].
Upon receiving a security bug report, the issue will be assigned to one of the project maintainers. This person will coordinate the related fix and release process, involving the following steps:
- Communicate with you to confirm we have received the report and provide you with a status update.
- You should receive this message within 48 - 72 business hours.
- Confirmation of the issue and a determination of affected versions.
- An audit of the codebase to find any potentially similar problems.
- Preparation of patches for all releases still under maintenance.
- These patches will be submitted as a separate pull request and contain a version update.
- This pull request will be flagged as a security fix.
- Once merged, and after post-merge unit testing has been completed, the patch will be immediately published to both PyPI repositories.