Skip to content

Security: jarpex/spotlight-js

SECURITY.md

Security Policy

We take the security of the Spotlight JS project seriously and appreciate the community's efforts in reporting vulnerabilities responsibly.

Supported Versions

We currently accept and prioritize vulnerability reports only for the latest stable version of the library. Users are strongly encouraged to always upgrade to the most recent release.

Version Supported
1.0.2
< 1.0.2

Reporting a Vulnerability

We ask that all newly discovered vulnerabilities be reported confidentially and responsibly before public disclosure.

How to Report

Do not use the public GitHub Issues tracker.

Vulnerability reports must be submitted through the GitHub Security Advisory feature in your repository. This process ensures that the vulnerability details are known only to the project maintainers until a patch is ready for release.

To submit a report:

  1. Navigate to the Security tab of your repository.

  2. Select Report a vulnerability.

There aren’t any published security advisories