Skip to content

docs: add a security policy - #13

Merged
GSTJ merged 1 commit into
masterfrom
docs/security-policy
Jul 28, 2026
Merged

docs: add a security policy#13
GSTJ merged 1 commit into
masterfrom
docs/security-policy

Conversation

@GSTJ

@GSTJ GSTJ commented Jul 28, 2026

Copy link
Copy Markdown
Owner

I added a security policy here, and the same file to the other four publishing repos: safe-jsx, magic, react-native-magic-modal and react-native-code-push-plugin. Only the advisory link differs between them.

It points at GitHub's private advisory form:
https://github.com/GSTJ/react-native-magic-toast/security/advisories/new

I turned private vulnerability reporting on for all five repos.

I left the version support table out. safe-jsx had one written in 2023 that still claimed 1.1.x was the supported line while the package sat at 1.3.4, and none of these packages keep backport branches. A table here would rot the same way. There's no response-time promise in it either, since that's not something anyone can hold to on a personal OSS project.

This one is a repo file only. I didn't touch any files array, and npm pack produces what it did before.

There was no SECURITY.md here, so a vulnerability report had nowhere to
go except a public issue. Private vulnerability reporting is enabled on
the repo now and the file points at the advisory form.

No version table and no response-time promise: there are no backport
branches to describe, and a stale support matrix is exactly what went
wrong with safe-jsx's copy.

Repo file only. The files array is untouched, so no published tarball
changes.
@GSTJ
GSTJ merged commit b773b6f into master Jul 28, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant