Skip to content

Security: Terminay/lessel

SECURITY.md

Security Policy

Supported Versions

We currently provide security updates for the latest major version of lessel.

Version Supported
0.1.x

Reporting a Vulnerability

If you discover a security vulnerability in lessel, please do not open a public issue.

Instead, send a private report via one of these methods:

  1. GitHub Security Advisories: Navigate to the repository's Security tab and click "Report a vulnerability".
  2. Email: [INSERT EMAIL ADDRESS]

We will acknowledge receipt within 48 hours and provide an estimated timeline for a fix.

What to Include

  • A description of the vulnerability.
  • Steps to reproduce (if possible).
  • Potential impact.
  • Any suggested mitigation (if known).

Disclosure Policy

We follow coordinated disclosure. We will:

  1. Acknowledge receipt within 48 hours.
  2. Investigate and develop a fix.
  3. Release a patched version.
  4. Publicly disclose after the fix is available.

We ask that you keep the vulnerability confidential until a patch is released.

Scope

This policy applies to all @lessel/* packages and their source code hosted in the Terminay/lessel repository. It does not apply to third-party dependencies.

There aren't any published security advisories