We release patches for security vulnerabilities for the following versions:
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
| < 0.1 | ❌ |
We take the security of portolan-cli seriously. If you believe you have found a security vulnerability, please report it to us as described below.
- Open a public GitHub issue for security vulnerabilities
- Disclose the vulnerability publicly before it has been addressed
-
Report via GitHub Security Advisories (preferred):
- Go to the Security tab
- Click "Report a vulnerability"
- Fill in the details
-
Email: If you prefer, you can email the maintainers at:
- nlebovits@pm.me
- Use subject line: "SECURITY: [brief description]"
- Type of vulnerability (e.g., SQL injection, path traversal, etc.)
- Full paths of source file(s) related to the vulnerability
- Location of the affected source code (tag/branch/commit or direct URL)
- Any special configuration required to reproduce the issue
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if possible)
- Impact of the issue, including how an attacker might exploit it
- Initial Response: Within 48 hours
- Status Update: Within 7 days with our evaluation
- Fix Timeline: Critical issues within 30 days, others within 90 days
- Credit: We will acknowledge your contribution in the release notes (unless you prefer to remain anonymous)
When using portolan-cli:
-
Keep Dependencies Updated
- Regularly update to the latest version
- Run
uv syncorpip install --upgrade portolan-cli - Monitor security advisories
-
Input Validation
- Validate file paths before processing
- Be cautious when processing files from untrusted sources
- Use the
--dry-runflag to preview operations
-
File Permissions
- Ensure proper file permissions on output directories
- Don't run with elevated privileges unless necessary
- Be aware of symlink attacks when processing files
-
Remote Files
- Verify URLs before processing remote files
- Use HTTPS when possible
- Be cautious with credentials in URLs
-
Environment
- Use virtual environments to isolate dependencies
- Don't commit sensitive data to version control
- Review generated files before sharing
- This tool reads and writes files to disk
- Users should validate file paths and permissions
- Processing untrusted files may expose system vulnerabilities
- The spatial extension is loaded for geometry operations
- Keep DuckDB updated to get security patches
- The tool can access remote files via HTTP/HTTPS
- Exercise caution with untrusted URLs
- Network requests are made to user-specified locations
- Security vulnerabilities will be disclosed after a fix is available
- We will publish a security advisory on GitHub
- Critical vulnerabilities will be highlighted in release notes
- CVE IDs will be requested for significant vulnerabilities
Security updates are delivered through:
- GitHub Security Advisories
- Release notes in CHANGELOG.md
- PyPI package updates
- GitHub Releases
If you have questions about security that are not vulnerabilities, please:
- Open a regular GitHub issue
- Use GitHub Discussions
- Contact maintainers via email
Thank you for helping keep portolan-cli and its users safe!