Security fixes are provided for the latest published version of each actively
maintained @rrulenet package. Older versions may not receive security fixes.
Please do not disclose suspected vulnerabilities in a public issue, discussion, or pull request.
Use GitHub's private vulnerability reporting in the repository that contains the affected package:
@rrulenet/rrule@rrulenet/core@rrulenet/recurrence@rrulenet/events@rrulenet/clin8n-nodes-rrulenet
If the issue affects multiple packages, submit a single report to any affected repository and identify all known affected packages. If you are unsure which repository is responsible, report it against the package through which you observed the vulnerability. We will coordinate the report across repositories as needed.
Please include, when available:
- the affected package and version;
- a description of the vulnerability and its potential impact;
- the steps, sample code, or proof of concept needed to reproduce it;
- relevant runtime, operating system, and configuration details;
- any known mitigations or suggested remediation.
We will review the report, confirm whether it is in scope, and communicate the next steps through the private advisory. Please allow time for investigation and remediation before any public disclosure. When appropriate, we will coordinate publication of an advisory and credit the reporter, unless anonymity is preferred.