Skip to content

Security

Please do not report a suspected vulnerability in a public issue. Use a private GitHub security advisory for this repository. If private reporting is unavailable, open a GitHub issue with only a high-level description and ask for a private contact; do not attach exploit code, private inputs, or credentials.

Include the affected package (pillow-rs, pillow-rs-py, or pillow-rs-js), version or commit, operating system, toolchain, and a minimal reproduction that contains no sensitive data. Please also say whether the issue affects decoding untrusted input, resource limits, memory safety, or the release and build pipeline.

The current branch and the latest tagged release are the supported reporting targets. Older commits and the deprecated fixture archives are retained for provenance and should not be assumed to receive fixes. Do not publish a disclosure until the maintainers have confirmed that a fix or mitigation is available.