Skip to content

Security: hebertcisco/ts-npm-package-boilerplate

SECURITY.md

Security Policy

Thank you for helping keep this project and its users safe.

Supported versions

This repository is a boilerplate. For this template itself, only the latest published version is actively supported with security updates. If you use this repository as a starting point for your own package, define and maintain a policy that fits your needs.

Version Supported
Latest release
Older releases ❔ Best-effort only

Reporting a vulnerability

Please do not open public GitHub issues for security vulnerabilities.

What to include

  • A description of the issue and potential impact.
  • Steps to reproduce or a proof of concept (PoC).
  • Affected versions, if known.
  • Any suggested mitigations.

Our process and SLAs

  • Triage within 2 business days.
  • Status updates at least weekly while under investigation.
  • If confirmed, we aim to publish a patch or mitigation within 14 days. Complex issues may take longer; we will communicate timelines.
  • We credit reporters in release notes if desired and appropriate.

Safe harbor

We will not pursue legal action for good-faith, non-destructive research that respects the following:

  • Do not access, modify, or exfiltrate data you do not own.
  • Do not degrade service or impact other users.
  • Do not perform social engineering or physical security testing.

Thank you for your responsible disclosure and for helping improve the security of the ecosystem.

There aren’t any published security advisories