Skip to content

Security: akshay-xp/distillate

SECURITY.md

Security Policy

Supported versions

distillate is pre-1.0. Security fixes are released against the latest 0.x version only. Pin a version if you depend on it, and upgrade to pick up fixes.

Version Supported
latest 0.x
older

Reporting a vulnerability

Do not open a public issue for security vulnerabilities.

Report privately through GitHub: on the repository's Security tab, choose Report a vulnerability. This opens a private advisory visible only to the maintainer.

Please include:

  • affected version(s) and runtime (Node, Bun, Deno, browser, edge);
  • a description of the issue and its impact;
  • a minimal reproduction, if possible.

This is a solo-maintained project, so responses are best-effort. You will get an acknowledgement as soon as the report is triaged, and coordination on a fix and disclosure timeline from there.

There aren't any published security advisories