| Version | Supported |
|---|---|
| 2.x | ✅ |
| 0.x | ❌ |
Please do not open a public issue for security-sensitive reports.
The preferred channel is GitHub's private security advisory flow:
→ https://github.com/WikipediaBrown/napkin/security/advisories/new
If you cannot use that flow, reach the maintainer via their GitHub profile.
I aim to acknowledge new reports within 5 business days and to provide a remediation plan or fix as soon as practical thereafter.
In scope:
- The napkin framework source under
Sources/napkin/.
Best-effort (not the primary security focus):
- GitHub Actions workflows under
.github/workflows/. - The
Examples/LaunchNapkinApp/example application.