| Version | Supported |
|---|---|
| 0.2.x | ✅ |
| 0.1.x | ✅ |
If you discover a security vulnerability in prisma-safe-delete, please report it responsibly.
Do not open a public GitHub issue for security vulnerabilities.
Instead, please use one of these methods:
-
GitHub Security Advisories (Preferred): Report via GitHub's private security advisory feature
-
Email: Contact the maintainer directly at the email address listed in their GitHub profile
When reporting, please provide:
- A description of the vulnerability
- Steps to reproduce the issue
- Potential impact
- Any suggested fixes (if applicable)
- Initial Response: Within 48 hours
- Status Update: Within 7 days
- Resolution Target: Within 30 days for critical issues
Once you report a vulnerability:
- You will receive an acknowledgment of your report
- We will investigate and keep you informed of progress
- We will notify you when the issue is fixed
- We will credit you in the release notes (unless you prefer to remain anonymous)
When using prisma-safe-delete:
- Keep your dependencies up to date
- Use the latest version of Prisma
- Follow Prisma's security best practices for database access
- Never expose your database credentials in client-side code
This security policy applies to the prisma-safe-delete npm package. Issues in dependencies should be reported to their respective maintainers.