Skip to content

Security: mastermunj/to-words

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
6.x βœ…
< 6.0 ❌

Users on an unsupported major version should upgrade to the latest release to continue receiving security fixes.

Reporting a Vulnerability

Please do NOT open a public GitHub issue for security vulnerabilities.

Use the private GitHub Security Advisory form instead:

πŸ‘‰ Report a vulnerability privately

We will:

  • Acknowledge your report within 48 hours.
  • Provide an estimated fix timeline within 5 business days.
  • Release a patch and publish a coordinated disclosure once the fix is available.

Scope

In scope Examples
βœ… Prototype pollution, ReDoS, arbitrary code execution via crafted input
βœ… Supply chain issues (malicious dependency, compromised release)
❌ Incorrect locale output for a specific number (file a regular issue)
❌ Missing locale or currency support (file a regular issue)

There aren't any published security advisories