Skip to content

Latest commit

 

History

History
36 lines (23 loc) · 1.45 KB

File metadata and controls

36 lines (23 loc) · 1.45 KB

Security Policy

Supported Versions

Only the latest version on the main branch is actively supported with security updates.

Version Supported
Latest Yes
Older No

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly.

Do not open a public issue. Instead, use one of these methods:

  1. GitHub Security Advisories (preferred): Report a vulnerability through GitHub's private reporting feature.
  2. Email: Contact the maintainer directly at the email address listed in the repository profile.

What to Include

  • A description of the vulnerability and its potential impact
  • Steps to reproduce or a proof of concept
  • The affected project(s) within the monorepo (caelundas, lexico, lexico-components, infrastructure)
  • Any suggested fixes, if available

Response Timeline

  • Acknowledgment: Within 48 hours of the report
  • Assessment: Within 7 days, you will receive an initial assessment of the vulnerability
  • Resolution: Critical vulnerabilities will be patched as quickly as possible; non-critical issues will be addressed in the next scheduled release

Disclosure Policy

We follow responsible disclosure. After a fix is released, the vulnerability details may be published in a security advisory. Reporters will be credited unless they prefer to remain anonymous.