Skip to content

Security: nqh-public/scheemer

Security

SECURITY.md

Security Policy

Supported Versions

We currently support the following versions with security updates:

Version Supported
1.0.x

Reporting a Vulnerability

If you discover a security vulnerability in Scheemer, please report it by emailing the maintainers or opening a private security advisory on GitHub.

Please do not report security vulnerabilities through public GitHub issues.

What to include in your report:

  • Type of issue (e.g. buffer overflow, SQL injection, cross-site scripting, etc.)
  • Full paths of source file(s) related to the issue
  • Location of the affected source code (tag/branch/commit or direct URL)
  • Any special configuration required to reproduce the issue
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if possible)
  • Impact of the issue, including how an attacker might exploit it

What to expect:

  • Acknowledgment of your report within 48 hours
  • Regular updates on the progress of addressing the vulnerability
  • Notification when the vulnerability is fixed

Security Best Practices

When using Scheemer:

  • Keep dependencies up to date by following Dependabot alerts
  • Review exported JSON data before sharing externally
  • Use the plugin only with trusted Framer projects
  • Report any suspicious behavior immediately

Thank you for helping keep Scheemer and its users safe!

There aren’t any published security advisories