mathematicskit is a scientific computing library (numerical mathematics algorithms and visualizations). It does not handle authentication, network services, or untrusted user input in the way a web application or server would — the realistic security surface is mainly:
- Deserializing untrusted data (e.g. loading a pickled/
.npyobject from an untrusted source and passing it into mathematicskit). - Vulnerabilities in dependencies (numpy, scipy, matplotlib, numba).
If you believe you've found a security vulnerability in mathematicskit, please do not open a public GitHub issue. Instead, use GitHub's private vulnerability reporting:
- Go to the repository's Security tab.
- Click Report a vulnerability.
If that's not available, open an issue asking a maintainer to contact you privately, without describing the vulnerability itself.
We'll acknowledge reports within a few days and aim to release a fix or mitigation promptly once a report is confirmed. Please give us reasonable time to address the issue before any public disclosure.
Only the latest released version on PyPI is supported with security fixes.