| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
We take the security of this project seriously. If you discover a security vulnerability, please follow these steps:
- Do NOT open a public issue.
- Send an advisory or report privately to the maintainers.
- Include detailed steps to reproduce the vulnerability, including sample code, environment details, and potential impact.
- Maintainers will acknowledge receipt within 48 hours and provide a timeline for a patch.
- Continuous Vulnerability Auditing: Automated found 0 vulnerabilities on every build and pull request.
- Static Application Security Testing (SAST): GitHub CodeQL scans all JavaScript/TypeScript code.
- Secret Scanning: TruffleHog scans all commits to prevent credential leakage.
- Least Privilege Tokens: GitHub Actions run with minimal necessary permissions.