| Version | Supported |
|---|---|
| 0.1.x | ✅ |
Do NOT open a public issue for security vulnerabilities.
Email the repository owner (see GitHub profile for contact)
Response time: < 48 hours. We will coordinate the fix and disclosure timeline.
This repository uses:
- CodeQL — semantic code analysis for JS/TS (runs on push, PR, and weekly schedule)
- Dependabot — automated dependency updates with security alerts
- Secret scanning — detects leaked credentials in commits
- Push protection — blocks commits containing secrets before they reach GitHub
- Dependency review — diffs dependency changes in PRs, blocks known-malicious packages
- npm audit — runs on every CI build
- Report privately — do not post publicly
- Allow 90 days for fix before public disclosure
- We will acknowledge within 48 hours
- Credit will be given in release notes (unless you request anonymity)