Atlas is a forkable frontend platform template. This document describes how maintainers handle security reports for the Atlas repository. It is not a contractual SLA, a certification, or a claim that Atlas is free of vulnerabilities.
Atlas supports the current release line on main after the latest intentional version merge.
Security and compatibility fixes are prioritized for that line.
| Line | Security fixes |
|---|---|
| Current Atlas 1.x on main | Yes — prioritized |
| Previous supported 1.x / 0.5.0 | Adjacent window only |
| Older 0.x snapshots | Only when explicitly stated |
| LTS | None at this stage |
See Releases and governance for versioning and support policy. Do not assume older tagged snapshots receive patches.
Do not disclose suspected vulnerabilities through a public GitHub issue.
Report privately using GitHub Private Vulnerability Reporting on this repository:
https://github.com/blitzcraftlabs/atlas/security/advisories/new
If that form is temporarily unavailable, contact a repository maintainer through a private channel. Do not invent or publish a security-contact email address.
Include:
- a description of the issue and affected Atlas surfaces;
- steps to reproduce, or a proof of concept that does not include real credentials;
- Atlas version, commit SHA, or downstream fork baseline if known;
- any mitigating configuration you already applied.
These are internal maintainer targets, not contractual SLAs.
| Severity | Acknowledge / triage | Remediation target (when practical) |
|---|---|---|
| Critical | Urgently, typically within 24–48 hours | ≤ 24–48 hours |
| High | ≤ 2 business days | ≤ 7 days |
| Moderate | ≤ 5 business days | ≤ 30 days |
| Low | Planned according to risk and release cycle | Next suitable release |
Severity for dependency findings follows the Atlas vulnerability policy
(security/policy.json): HIGH and CRITICAL block CI unless a
machine-readable, time-limited exception is in force.
Atlas security fixes land on main, then ship to downstream Atlas consumers through the existing
upgrade and fix-propagation machinery — not as an independent npm security product.
See:
Typical path:
security fix → Atlas main → versioned Atlas snapshot / migration notes → consumer upgrade
Auth session code and lib/security/** are high-scrutiny synced surfaces. Customized consumer
copies are merge-required during upgrades.
Keep Atlas CI distinct from GitHub-native products:
- Atlas-owned merge gates — Secrets Scan (Gitleaks) and Security Audit
(
pnpm security:check) are required status checks onmain, with Governance, CI, and UI Quality. - GitHub CodeQL code scanning — default setup is enabled on
blitzcraftlabs/atlas. It is not a required merge gate and is not a substitute for private vulnerability reports. - GitHub Code Quality — a separate GitHub maintainability product; not currently configured.
Those GitHub-native settings are not packaged into generated Atlas consumers. See security engineering.