Skip to content

Latest commit

 

History

History
29 lines (17 loc) · 1.08 KB

File metadata and controls

29 lines (17 loc) · 1.08 KB

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this project, do not open a public issue. Please report it privately so a fix can be released before details become public.

Email: ezzouine.a@gmail.com

Please include:

  • A description of the issue and its impact
  • Steps to reproduce (proof-of-concept code, affected package and version)
  • Any suggested mitigation, if known

You can expect:

  • An acknowledgement within 72 hours
  • An initial assessment within 7 days
  • A patched release as soon as a fix is validated; coordinated disclosure timing will be agreed with the reporter

Supported Versions

Only the latest published @elasticias/* package versions receive security fixes. Pin to a current version and update promptly when a security release is published.

Scope

In scope: code in this repository and the @elasticias/* npm packages it produces.

Out of scope: vulnerabilities in upstream dependencies (please report those to the upstream project), and issues in consuming applications that are not caused by this library.