Skip to content

Security: laphilosophia/strime

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
3.x
2.x
< 2.0

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, please email me@erdem.work with:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes (optional)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 1 week
  • Resolution: Depending on severity, typically within 30 days

What to Expect

  1. Confirmation that we received your report
  2. Assessment of the vulnerability
  3. Regular updates on our progress
  4. Credit in the release notes (if desired)

Scope

This policy applies to the Strime core library (strime npm package).

Third-party dependencies are outside the scope of this policy, but we will coordinate with upstream maintainers when relevant.

There aren’t any published security advisories