Security fixes are applied to the latest stable release line. Older lines do not receive security backports.
| Version | Supported |
|---|---|
| 1.3.x | ✅ |
| < 1.3 | ❌ |
Please do not open a public GitHub issue for security vulnerabilities.
Report vulnerabilities privately through one of these channels:
- GitHub private vulnerability reporting (preferred): use the "Report a vulnerability" button on the repository's Security tab at https://github.com/ZhenHaoFu810/StataFlow/security/advisories/new.
- Email: zhenhaofu2001@gmail.com
Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce or a proof of concept
- Affected versions, if known
You can expect an acknowledgment within 7 days. We will investigate, develop a fix, and coordinate disclosure with you before publishing any advisory. We ask that you keep the report confidential until a fix is released.
- StataFlow's
stata_runnerlayer executes locally generated Stata.dofiles viasubprocesswithshell=True. Only.docontent generated by the project itself should ever be passed to it. If you find a path where untrusted input can reach Stata execution, that is in scope and should be reported privately. - Dependency vulnerabilities should be reported when StataFlow's version constraints permit an affected version.