Skip to content

Security: Yasirdora/draftfirst

Security

SECURITY.md

Security policy

Supported versions

Security fixes are provided for the latest published minor release of @draftfirst/core. Pre-release versions may receive fixes without backports.

Reporting a vulnerability

Please use GitHub's private vulnerability reporting for Yasirdora/draftfirst. Do not open a public issue for a suspected vulnerability.

Include the affected version, a minimal reproduction, expected impact, and any known mitigations. Reports will be acknowledged as soon as practicable. A fix and coordinated disclosure timeline will be agreed before publication.

Draft First processes potentially untrusted screenplay files. Reports involving resource exhaustion, malformed Fountain/FDX input, data loss, or package supply chain integrity are explicitly in scope.

There aren't any published security advisories