Files
backnotprop__plannotator/SECURITY.md
Michael Ramos d4ce3dcb57 ci: harden releases and add security scanning (#1274)
* ci: harden release and add security scanning

* Harden release and deploy recovery paths

* Fix npm artifact pack destinations
2026-08-12 11:40:15 -07:00

1.0 KiB

Security Policy

Supported versions

Plannotator is actively developed. Security fixes are provided for the latest released version. Older releases are not supported; users should update before reporting a problem that may already be fixed.

Version Supported
Latest release Yes
Older releases No

Reporting a vulnerability

Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting form so the report and any follow-up remain confidential while the issue is assessed.

Include, when available:

  • the affected version and component;
  • steps or a minimal example that reproduces the issue;
  • the security impact and required preconditions;
  • any known workarounds or suggested remediation.

Please avoid public disclosure until a fix or coordinated disclosure plan is available. Maintainers will use the private advisory to confirm the report, coordinate remediation, and credit the reporter when requested.