Skip to content

Security: Bounteous-Inc/composer-darn

Security

SECURITY.md

Security Policy

Supported versions

Only the latest stable release receives security fixes. If no stable release has been made, patches are applied to main.

Reporting a vulnerability

Please do not open a public pull request or issue for security vulnerabilities.

Report vulnerabilities privately via GitHub's private vulnerability reporting or by emailing the maintainer directly. Include:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce or a proof-of-concept
  • Any suggested remediation if you have one

You can expect an acknowledgement within 48 hours and a resolution timeline within 5 business days of triage.

There aren't any published security advisories