Skip to content

Security: jrmybtlr/usemods

SECURITY.md

Security Policy

Supported Versions

Use this section to tell people about which versions of your project are currently being supported with security updates.

Version Supported
5.1.x
5.0.x
4.0.x
< 4.0

Reporting a Vulnerability

Use this section to tell people how to report a vulnerability.

Tell them where to go, how often they can expect to get an update on a reported vulnerability, what to expect if the vulnerability is accepted or declined, etc.

Security Policy

Supported Versions

The following versions of this project are currently supported with security updates:

Version Supported
1.x
< 1.0

We generally support the latest major version and provide security fixes for a reasonable period after each release. Older, unsupported versions will not receive security patches and may contain known vulnerabilities.

Reporting a Vulnerability

If you discover a security vulnerability in this project, we would appreciate your help in disclosing it to us responsibly.

Please email your report to: security@usemods.app (or your preferred contact address).

When reporting, please include:

  • A description of the issue and its potential impact.
  • Steps to reproduce the vulnerability.
  • Any relevant logs, proof-of-concept code, or configuration details.
  • Your operating system, runtime (Node / browser), and version information, if applicable.

If you prefer, you may also open a private security advisory on GitHub instead of a public issue.

Our Response Process

  1. We will acknowledge your report as soon as possible, typically within 3 business days.
  2. We will investigate the issue and may contact you for additional information.
  3. Once confirmed, we will:
    • Develop and test a fix.
    • Prepare a release that includes the fix.
    • Publish a security advisory describing the vulnerability, its impact, and mitigation steps.
  4. We will notify you when the fix is released and, if you agree, credit you for the discovery in the advisory.

We aim to resolve critical issues as quickly as possible. Less severe issues may be batched into regular releases.

Preferred Communication and Encryption

If you require secure communication, please request our PGP key in your initial email and we will provide details for encrypted correspondence.

Public Issues vs. Private Reports

Please do not file public GitHub issues for suspected security vulnerabilities.

Public issues make it easier for malicious actors to discover and exploit the problem before a fix is available. Use the private reporting methods described above so we can address the vulnerability safely.

Scope

This security policy applies to:

  • The source code in this repository.
  • Official releases and packages we publish (for example, on npm).

It does not cover:

  • Third-party dependencies (though we may coordinate upstream reports where appropriate).
  • Forks or modified versions of this project maintained by others.
  • Services or infrastructure operated by third parties.

Responsible Disclosure

We strongly support responsible disclosure. Please give us a reasonable amount of time to investigate and remediate the issue before any public disclosure.

If you believe we have not responded in a reasonable timeframe, you may choose to disclose the vulnerability publicly, but we kindly ask that you:

  • Avoid sharing exploit details that make it trivial to reproduce and weaponize the issue.
  • Clearly describe that you attempted private disclosure first.

Thank you for helping keep this project and its users secure.

There aren't any published security advisories