Skip to content

Security: PyThaiNLP/pythainlp

SECURITY.md

Security Policy

Supported Versions

Version Supported
5.3.x ✅
5.2.x ✅
5.1.x ❌
5.0.x ❌
4.0.x ❌
3.1.x ❌
3.0.x ❌
2.3.x ❌
2.2.x ❌
2.1.x ❌
2.0.x ❌
< 2.0 ❌

Verify release files

Releases after version 5.3.8 attach these files to each GitHub release:

  • the wheel and the source distribution (sdist), as published on PyPI;
  • the software bill of materials (SBOM), pythainlp-<version>.spdx3.json, byte-identical to the SBOM embedded in the wheel at .dist-info/sboms/ (PEP 770);
  • a Sigstore bundle (<file>.sigstore.json) for each of the three files above.

Each of the three files also has a GitHub artifact attestation (build provenance).

To verify a downloaded file, put <file> and <file>.sigstore.json in the same directory, then run:

pip install sigstore
python -m sigstore verify github <file> \
  --cert-identity https://github.com/PyThaiNLP/pythainlp/.github/workflows/pypi-publish.yml@refs/tags/v<version>
gh attestation verify <file> -R PyThaiNLP/pythainlp \
  --signer-workflow PyThaiNLP/pythainlp/.github/workflows/pypi-publish.yml \
  --source-ref refs/tags/v<version>

<file> is the wheel, the sdist, or the SBOM.

Future Security Recommendations

The following security improvements are planned for future releases:

  • Migrate from pickle to a safer serialization format such as JSON or MessagePack.
  • Upgrade the hashing algorithm for integrity verification from MD5 to SHA-256 or SHA-3.
  • Implement digital signatures for corpus files to ensure authenticity.
  • Add version tracking to the corpus to prevent rollback attacks.

There aren't any published security advisories