Skip to content

Security: ahmtkm/TrEInvoice

Security

SECURITY.md

Security

Security

Please report suspected vulnerabilities privately to the project maintainers. Do not include credentials, personal data, tax identifiers, or real invoice data in an issue.

XML changes must preserve DTD prohibition, a null resolver, a bounded document size, malformed-input rejection, and caller-owned stream lifetime. The reader is synchronous and does not provide cancellation; applications handling untrusted uploads should also enforce request timeouts and concurrency limits.

There aren't any published security advisories