Skip to content

Security: castdrian/thor-when

Security

SECURITY.md

security policy

reporting

Please do not open a public issue for a security vulnerability. Use GitHub’s private vulnerability reporting for this repository when enabled, or contact the repository owner through the GitHub profile.

scope

thor when? is a static client-side app. It does not receive private order data, credentials, addresses, tracking numbers, or payment information. Reports involving unsafe external links, dependency vulnerabilities, workflow permissions, data-ingestion bypasses, or script injection are in scope.

There aren't any published security advisories