The project is pre-1.0 and under active development. Security fixes are applied
to the latest released version of each @oh-just-another/* package on npm
and to the master branch. Older versions are not maintained.
Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.
Instead, use one of the private channels:
- GitHub Security Advisories — open a private report via the Security advisories page of this repository (preferred).
- Email —
rustam@n69.in.
Please include as much detail as you can:
- the affected package(s) and version(s),
- a description of the issue and its impact,
- steps to reproduce or a proof of concept,
- any suggested mitigation.
- We aim to acknowledge a report within a few days.
- We will investigate, keep you informed of progress, and credit you in the advisory once a fix is released (unless you prefer to remain anonymous).
- Please give us a reasonable window to release a fix before any public disclosure.
Thank you for helping keep the project and its users safe.