| Version | Supported |
|---|---|
| 0.3.x | ✅ |
| < 0.3 | ❌ |
We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly.
Please do NOT report security vulnerabilities through public GitHub issues.
Instead, please report them via one of the following methods:
-
GitHub Private Vulnerability Reporting: Use GitHub's private vulnerability reporting feature.
-
Email: Contact the maintainers directly (if email is available in the repository).
When reporting a vulnerability, please include:
- Description: A clear description of the vulnerability
- Impact: The potential impact of the vulnerability
- Steps to Reproduce: Detailed steps to reproduce the issue
- Affected Versions: Which versions are affected
- Possible Fix: If you have suggestions for fixing the issue
- Acknowledgment: Within 48 hours of receiving your report
- Initial Assessment: Within 1 week
- Resolution Timeline: Depends on severity, but we aim for:
- Critical: 24-48 hours
- High: 1 week
- Medium: 2 weeks
- Low: Next release cycle
- Acknowledgment: We will acknowledge receipt of your report
- Communication: We will keep you informed of our progress
- Credit: We will credit you in the security advisory (unless you prefer anonymity)
- Coordinated Disclosure: We will coordinate the disclosure timeline with you
When using Logust in your projects:
- Ensure log files have appropriate permissions
- Avoid logging to world-writable directories
- Consider using
compression=Truefor archived logs
- Never log sensitive data such as passwords, API keys, or personal information
- Use the
filterparameter to exclude sensitive records:
def filter_sensitive(record):
return "password" not in record.get("message", "").lower()
logger.add("app.log", filter=filter_sensitive)- Be cautious when logging user input
- Sanitize or validate user input before logging
- Use structured logging (JSON) when possible
from logust import logger
# Production configuration
logger.add(
"app.log",
level="INFO", # Don't use DEBUG in production
rotation="100 MB", # Prevent disk exhaustion
retention="30 days", # Clean up old logs
compression=True, # Reduce storage
serialize=True, # Structured logs for analysis
)Logust depends on:
- Rust crates: Regularly audited via
cargo audit - Python packages: Minimal runtime dependencies
We monitor for security advisories in our dependencies and update promptly when vulnerabilities are discovered.
Security updates will be released as patch versions (e.g., 0.3.2, 0.3.3) and announced via:
- GitHub Security Advisories
- Release notes
We recommend always using the latest version of Logust.