Skip to content

Security: openeudi/core

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.1.x Yes

Only the latest release receives security updates.

Reporting a Vulnerability

Do not open a public issue for security vulnerabilities.

Use GitHub's Private Vulnerability Reporting:

  1. Go to the Security tab of this repository
  2. Click "Report a vulnerability"
  3. Fill in the details

Response Timeline

  • Acknowledge: Within 72 hours
  • Assessment: Within 1 week
  • Patch (critical): Within 30 days
  • Patch (non-critical): Next scheduled release

After Resolution

  • Security advisory published on GitHub
  • Reporter credited (unless they prefer anonymity)
  • Fix noted in CHANGELOG.md

Scope

This policy covers the @openeudi/core npm package. For issues in dependencies, please report to the respective maintainers.

There aren’t any published security advisories