mirror of
https://github.com/backnotprop/plannotator.git
synced 2026-09-14 14:17:26 +08:00
d4ce3dcb57
* ci: harden release and add security scanning * Harden release and deploy recovery paths * Fix npm artifact pack destinations
1.0 KiB
1.0 KiB
Security Policy
Supported versions
Plannotator is actively developed. Security fixes are provided for the latest released version. Older releases are not supported; users should update before reporting a problem that may already be fixed.
| Version | Supported |
|---|---|
| Latest release | Yes |
| Older releases | No |
Reporting a vulnerability
Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting form so the report and any follow-up remain confidential while the issue is assessed.
Include, when available:
- the affected version and component;
- steps or a minimal example that reproduces the issue;
- the security impact and required preconditions;
- any known workarounds or suggested remediation.
Please avoid public disclosure until a fix or coordinated disclosure plan is available. Maintainers will use the private advisory to confirm the report, coordinate remediation, and credit the reporter when requested.