Skip to content

Security: andrsrxn/icons

SECURITY.md

Security Policy

Supported Versions

We actively maintain and provide security updates for the latest major version of @andrsrxn/icons.

Version Supported
1.x
< 1.0

Reporting a Vulnerability

We take the security of @andrsrxn/icons seriously. If you believe you have discovered a security vulnerability, please do not report it through public GitHub issues, pull requests, or discussions.

Instead, please report vulnerabilities exclusively through GitHub's Private Vulnerability Reporting:

  1. Go to the main repository page for @andrsrxn/icons on GitHub.
  2. Click on the Security tab located under the repository title.
  3. In the left sidebar under Reporting, click on Report a vulnerability.
  4. Fill out the security advisory form with as much detail as possible, including:
    • A description of the vulnerability and its potential impact.
    • Step-by-step instructions (or a minimal reproduction example) to demonstrate the issue.
    • Any suggested mitigations or fixes, if available.

Disclosure & Resolution Process

  • Acknowledgment: We will acknowledge receipt of your report within 48 hours.
  • Assessment: We will evaluate the vulnerability in private and determine its severity and impact.
  • Fix & Patch: If validated, a patch release will be created and published to npm as soon as possible.
  • Public Advisory: Once a resolution is published, we will disclose the advisory publicly and credit you for the responsible disclosure (unless you request to remain anonymous).

Thank you for helping keep @andrsrxn/icons and the open-source ecosystem safe!

There aren't any published security advisories