| Version | Supported |
|---|---|
| 1.x | Yes |
| < 1.0 | No |
If you discover a security vulnerability in scrapr (such as remote code execution, prototype pollution, unsafe deserialization, or SSRF in network handlers):
- Do not create a public GitHub issue.
- Report the vulnerability privately via GitHub Security Advisories tab under
Security>Advisories>Report a vulnerability. - If GitHub Advisories is unavailable, email the maintainer directly at
riazrepo@gmail.com.
- Detailed description of the issue.
- Step-by-step reproduction code or minimal proof-of-concept.
- Potential impact and affected platforms/methods.
Upstream third-party web resolvers changing their HTML or breaking their endpoints is considered a functional bug, not a security vulnerability. Please report broken scrapers through public issues.