We currently provide security updates for the latest major version of lessel.
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
If you discover a security vulnerability in lessel, please do not open a public issue.
Instead, send a private report via one of these methods:
- GitHub Security Advisories: Navigate to the repository's Security tab and click "Report a vulnerability".
- Email: [INSERT EMAIL ADDRESS]
We will acknowledge receipt within 48 hours and provide an estimated timeline for a fix.
- A description of the vulnerability.
- Steps to reproduce (if possible).
- Potential impact.
- Any suggested mitigation (if known).
We follow coordinated disclosure. We will:
- Acknowledge receipt within 48 hours.
- Investigate and develop a fix.
- Release a patched version.
- Publicly disclose after the fix is available.
We ask that you keep the vulnerability confidential until a patch is released.
This policy applies to all @lessel/* packages and their source code hosted in the Terminay/lessel repository. It does not apply to third-party dependencies.