Skip to content

Security: jscraik/trace-narrative

SECURITY.md

Security Policy

Supported versions

We apply security fixes to the latest release line.

Version Supported
Latest release Yes
Older releases No

Reporting a vulnerability

Please do not open a public issue for security vulnerabilities.

Use GitHub's private vulnerability reporting flow:

If private reporting is unavailable, contact the maintainer through the options listed on @jscraik's GitHub profile and include:

  1. Affected version and platform
  2. Reproduction steps or proof-of-concept
  3. Potential impact
  4. Any suggested mitigation

Response targets

  • Initial acknowledgment: within 5 business days
  • Triage decision: within 10 business days
  • Fix timeline: depends on severity and complexity

We will coordinate disclosure timing with reporters whenever possible.

There aren’t any published security advisories