| Version | Status |
|---|---|
| 2.x | Active. Bug fixes and security patches. |
| 1.x | End of life. No further updates. Upgrade to 2.x (no breaking changes to the Rosemary class API). |
| < 1.0 | Deprecated since 1.1.0. Do not use. |
Email: luisfer.romero.calero@gmail.com
Do not open a public GitHub issue for a suspected vulnerability. Use email so the issue can be assessed before any public disclosure.
Please include:
- The affected version (
npm ls rosemary-js). - A minimal reproduction.
- The impact (data exposure, code execution, denial of service, etc.).
- Any suggested fix, if you have one.
- Acknowledgement within 7 days.
- A fix or a written reason for not fixing within 30 days.
- Coordinated disclosure timeline agreed with the reporter, with a default of 90 days from acknowledgement.
- Credit in the release notes if the reporter wants it.