If you find a security issue in secdata-scrapers itself — for example, a way the tool could be used to bypass robots.txt checking, a credential leakage bug in the audit logger, or a path traversal in file handling — please report it responsibly rather than opening a public issue.
To report: Email [yourdearestdaniel@gmail.com] with subject "secdata-scrapers security"
Include:
- Description of the issue
- Steps to reproduce
- Potential impact
- Any suggested fix
We will respond within 72 hours and credit you in the changelog if you wish.
In scope: bugs in the scraper code, compliance checks, content safety filters, audit logging, or storage utilities that could cause harm if exploited.
Out of scope: vulnerabilities in third-party sources we scrape (report those to the source directly), theoretical issues with no practical exploitation path.