Skip to content

Security: jooy2/diffine

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Report it privately, through GitHub's own advisory page: https://github.com/jooy2/diffine/security/advisories/new.

Please do not open an ordinary issue for a vulnerability, and please do not describe one in a pull request. Both are public from the moment they are created, and a report that is public before there is a fix puts everyone using the package at risk.

A report is more useful with the version it affects, the environment it happens in, and the smallest example that shows it.

Which versions are fixed

The latest published version of each package. Diffine is before 1.0.0, so there are no maintained release branches behind it, and the fix for anything reported is a new version rather than a patch to an old one.

What happens next

A report is acknowledged, investigated and, where it is confirmed, fixed and released. Whoever is affected is told what to update to and what the problem was, once the fix is out.

If you would rather be credited by name in that note, say so in the report. Otherwise reports are handled without naming the reporter.

What we ask of anyone using the package

Stay on the latest version. It is the one that carries the fixes.

Contact

There aren't any published security advisories