| Version | Supported |
|---|---|
| 0.x.x | ✅ |
If you discover a security vulnerability within this project, please report it responsibly.
Please do NOT open a public GitHub issue for security vulnerabilities.
Instead, please send an email to the maintainers with:
- A description of the vulnerability
- Steps to reproduce the issue
- Potential impact assessment
- Any suggested fixes (optional)
We will acknowledge receipt of your report within 48 hours and provide a more detailed response within 7 days, indicating the next steps in handling your submission.
When using perflock:
- Keep dependencies updated: Regularly update to the latest version
- Review configuration: Ensure performance contracts don't expose sensitive timing information
- CI/CD security: Protect your
NPM_TOKENand other secrets in GitHub Actions
Thank you for helping keep perflock secure!