We actively maintain and provide security updates for the latest major version of @andrsrxn/icons.
| Version | Supported |
|---|---|
| 1.x | ✅ |
| < 1.0 | ❌ |
We take the security of @andrsrxn/icons seriously. If you believe you have discovered a security vulnerability, please do not report it through public GitHub issues, pull requests, or discussions.
Instead, please report vulnerabilities exclusively through GitHub's Private Vulnerability Reporting:
- Go to the main repository page for
@andrsrxn/iconson GitHub. - Click on the Security tab located under the repository title.
- In the left sidebar under Reporting, click on Report a vulnerability.
- Fill out the security advisory form with as much detail as possible, including:
- A description of the vulnerability and its potential impact.
- Step-by-step instructions (or a minimal reproduction example) to demonstrate the issue.
- Any suggested mitigations or fixes, if available.
- Acknowledgment: We will acknowledge receipt of your report within 48 hours.
- Assessment: We will evaluate the vulnerability in private and determine its severity and impact.
- Fix & Patch: If validated, a patch release will be created and published to npm as soon as possible.
- Public Advisory: Once a resolution is published, we will disclose the advisory publicly and credit you for the responsible disclosure (unless you request to remain anonymous).
Thank you for helping keep @andrsrxn/icons and the open-source ecosystem safe!