Skip to content

Security: ZhenHaoFu810/StataFlow

Security

SECURITY.md

Security Policy

Supported Versions

Security fixes are applied to the latest stable release line. Older lines do not receive security backports.

Version Supported
1.3.x ✅
< 1.3 ❌

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Report vulnerabilities privately through one of these channels:

Please include:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce or a proof of concept
  • Affected versions, if known

You can expect an acknowledgment within 7 days. We will investigate, develop a fix, and coordinate disclosure with you before publishing any advisory. We ask that you keep the report confidential until a fix is released.

Scope Notes

  • StataFlow's stata_runner layer executes locally generated Stata .do files via subprocess with shell=True. Only .do content generated by the project itself should ever be passed to it. If you find a path where untrusted input can reach Stata execution, that is in scope and should be reported privately.
  • Dependency vulnerabilities should be reported when StataFlow's version constraints permit an affected version.

There aren't any published security advisories