
Python Cryptographic Authority
External Program
Submit bugs directly to this organization


External Program
Submit bugs directly to this organization
This page can be used for reporting security vulnerabilities in any of the Python Cryptographic Authority family of libraries.
Because we're building libraries for security, we take a very broad view of what constitutes a security vulnerability. Our definition for a vulnerability is:
Anytime it’s possible to write code using the library's public API which does not provide the guarantees that a reasonable developer would expect it to based on our documentation.
For our web properties we are interested in any typical web vulnerabilities. Please note that our websites are all (so far as we know) static.
The following findings do not qualify: