Skip to content

Security: rrulenet/rrule

SECURITY.md

Security Policy

Supported versions

Security fixes are provided for the latest published version of each actively maintained @rrulenet package. Older versions may not receive security fixes.

Reporting a vulnerability

Please do not disclose suspected vulnerabilities in a public issue, discussion, or pull request.

Use GitHub's private vulnerability reporting in the repository that contains the affected package:

If the issue affects multiple packages, submit a single report to any affected repository and identify all known affected packages. If you are unsure which repository is responsible, report it against the package through which you observed the vulnerability. We will coordinate the report across repositories as needed.

Please include, when available:

  • the affected package and version;
  • a description of the vulnerability and its potential impact;
  • the steps, sample code, or proof of concept needed to reproduce it;
  • relevant runtime, operating system, and configuration details;
  • any known mitigations or suggested remediation.

We will review the report, confirm whether it is in scope, and communicate the next steps through the private advisory. Please allow time for investigation and remediation before any public disclosure. When appropriate, we will coordinate publication of an advisory and credit the reporter, unless anonymity is preferred.

There aren't any published security advisories