Skip to content

Security: joinhottub/hottub-python

Security

SECURITY.md

Security policy

Supported versions

Security fixes are provided for the latest release of the hottub Python package.

Reporting a vulnerability

Email feedback@joinhottub.com with [security: hottub-python] in the subject and include reproduction steps and the affected version.

Do not open a public GitHub issue for a suspected vulnerability. Do not include Hottub access tokens, passwords, recovery codes, personal information, or other secrets in reports, examples, logs, or test fixtures.

We aim to acknowledge reports within 48 hours and fix critical issues within 7 days.

Package boundary

This repository contains a small API client and CLI. It must never contain Hottub production credentials, private monorepo content, or Harmonic Engine source, algorithms, coefficients, models, benchmarks, debug state, symbols, or binary artifacts.

There aren't any published security advisories