Skip to content

Security: oh-just-another/diagram

SECURITY.md

Security Policy

Supported versions

The project is pre-1.0 and under active development. Security fixes are applied to the latest released version of each @oh-just-another/* package on npm and to the master branch. Older versions are not maintained.

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.

Instead, use one of the private channels:

  • GitHub Security Advisories — open a private report via the Security advisories page of this repository (preferred).
  • Email — rustam@n69.in.

Please include as much detail as you can:

  • the affected package(s) and version(s),
  • a description of the issue and its impact,
  • steps to reproduce or a proof of concept,
  • any suggested mitigation.

What to expect

  • We aim to acknowledge a report within a few days.
  • We will investigate, keep you informed of progress, and credit you in the advisory once a fix is released (unless you prefer to remain anonymous).
  • Please give us a reasonable window to release a fix before any public disclosure.

Thank you for helping keep the project and its users safe.

There aren't any published security advisories