If you believe you have found a security vulnerability in z4j-celerybeat,
do not open a public GitHub issue. Email [email protected] instead.
We acknowledge reports within 48 hours, provide a preliminary assessment within 5 business days, and target fixes within 30 days (7 days for confirmed critical issues). Reporting timelines, safe harbor, supported-version policy, and published advisories are maintained in the canonical z4j project security policy.
This adapter inventories static Celery Beat configuration and, when
django-celery-beat is present, executes authenticated create, update, toggle,
trigger, and delete controls with the application's Django database access.
Schedule argument mapping, backend selection, ORM mutation, and indeterminate
timeouts are package-specific security surfaces; transport, redaction, and
authorization policy remain owned by z4j-core and the brain.