Skip to content

Security: viscalyx/developer-mode

Security

SECURITY.md

Security Policy

Supported versions

Only the most recent minor of each @viscalyx/developer-mode-* package receives security fixes. Older minors are upgraded by bumping to the latest.

Reporting a vulnerability

Please do not open a public GitHub issue for security problems.

Use GitHub's private security advisory flow to report a vulnerability. We acknowledge reports within five working days and aim to ship a fix within 30 days for confirmed issues.

When reporting, please include:

  • The affected package and version.
  • A minimal reproduction or proof of concept.
  • Your assessment of impact (what an attacker can do).

Disclosure

Once a fix is released we publish a GitHub Security Advisory and credit the reporter (unless they prefer to remain anonymous).

There aren't any published security advisories