Skip to content

Security: bitilia/vcoder

Security

SECURITY.md

Security policy

Our honest security promise

VCoder helps you handle input safely. It does not claim to prevent injection or to sanitize all input. Security is context-dependent, and no library can make arbitrary untrusted input safe in every situation. We deliberately avoid misleading guarantees.

What VCoder protects against

  • Path traversal — detects .. (raw, percent-encoded, double-encoded, Unicode-normalized) and NUL bytes; anchors resolved paths within an allowed root (vcoder.path).
  • Shell injection — subprocess wrappers use argument lists only, never a shell; reject NUL bytes; and can constrain executables to allowed directories (vcoder.subprocess).
  • Accidental SQL string-building — query builders bind values as parameters and validate identifiers; guard_query flags obvious formatting mistakes (vcoder.sql).
  • XSS from untrusted text — context-aware HTML escaping for text nodes and quoted attributes (vcoder.html).
  • Weak passwords — configurable strength policy, common-password detection, and an optional privacy-preserving HIBP check (vcoder.passwords).
  • Unsafe filenames — rejects illegal characters, reserved Windows device names, path separators, and over-long names (vcoder.filesystem).

What VCoder does NOT protect against

  • TOCTOU / filesystem races. A path validated now can change before use.
  • Symlink / hardlink attacks beyond resolution-time checks.
  • Dangerous programs. Not using a shell stops shell injection, but the program you invoke may still mishandle its arguments (find -exec, ssh, tar).
  • SQL you build yourself. If you interpolate a value into a query string, no library can retroactively separate data from code. Always pass parameters.
  • Rich HTML sanitization. safe_html escapes everything; to allow a subset of tags use a dedicated allow-list sanitizer (e.g. bleach).
  • Definitive password strength. Estimates are approximate; always hash with a slow KDF before storage.

Treat VCoder as one layer of defense in depth. Run with least privilege, validate on the server, and use parameterized queries and argument-list subprocesses everywhere.

Handling of secrets

  • Password and secret=True inputs are read without echoing.
  • Secrets are never logged; ValidationError never includes the offending value in its string form.
  • The HIBP check sends only the first five characters of a SHA-1 hash (k-anonymity) and is never called unless you opt in.

Supported versions

Version Supported
0.1.x ✅

Reporting a vulnerability

Please report suspected vulnerabilities privately rather than opening a public issue.

  • Use GitHub's "Report a vulnerability" (Security → Advisories) on the repository, or
  • email the maintainers listed in pyproject.toml.

Include a description, reproduction steps, affected versions, and any suggested remediation. We aim to acknowledge reports within a few business days and will coordinate a fix and disclosure timeline with you. Please give us reasonable time to remediate before any public disclosure.

There aren't any published security advisories