If you discover a security vulnerability in this project, do not open a public issue. Please report it privately so a fix can be released before details become public.
Email: ezzouine.a@gmail.com
Please include:
- A description of the issue and its impact
- Steps to reproduce (proof-of-concept code, affected package and version)
- Any suggested mitigation, if known
You can expect:
- An acknowledgement within 72 hours
- An initial assessment within 7 days
- A patched release as soon as a fix is validated; coordinated disclosure timing will be agreed with the reporter
Only the latest published @elasticias/* package versions receive security fixes. Pin to a current version and update promptly when a security release is published.
In scope: code in this repository and the @elasticias/* npm packages it produces.
Out of scope: vulnerabilities in upstream dependencies (please report those to the upstream project), and issues in consuming applications that are not caused by this library.