Skip to content

Security: luisfer/rosemary-js

Security

SECURITY.md

Security policy

Supported versions

Version Status
2.x Active. Bug fixes and security patches.
1.x End of life. No further updates. Upgrade to 2.x (no breaking changes to the Rosemary class API).
< 1.0 Deprecated since 1.1.0. Do not use.

Reporting a vulnerability

Email: luisfer.romero.calero@gmail.com

Do not open a public GitHub issue for a suspected vulnerability. Use email so the issue can be assessed before any public disclosure.

Please include:

  • The affected version (npm ls rosemary-js).
  • A minimal reproduction.
  • The impact (data exposure, code execution, denial of service, etc.).
  • Any suggested fix, if you have one.

What to expect

  • Acknowledgement within 7 days.
  • A fix or a written reason for not fixing within 30 days.
  • Coordinated disclosure timeline agreed with the reporter, with a default of 90 days from acknowledgement.
  • Credit in the release notes if the reporter wants it.

There aren't any published security advisories