Security fixes are applied to the latest released version of cnkit.
Please do not open a public issue for a suspected vulnerability involving
credential exposure, unsafe network behavior or a dependency compromise.
Email Saurav Kumar at kumar.saurav@gmail.com with:
- the affected version;
- a minimal reproduction;
- the impact you believe is possible; and
- whether the report may be acknowledged publicly after a fix is available.
The package contains no authentication code and stores no credentials. Its optional data fetchers make unauthenticated HTTPS requests to public USGS and USDA services. Reports about incorrect hydrologic results are also welcome, but may be handled as scientific correctness issues rather than security vulnerabilities.