Skip to content

Security: AxLabs/atlas

Security

SECURITY.md

Security Policy

Atlas is a forkable frontend platform template. This document describes how maintainers handle security reports for the Atlas repository. It is not a contractual SLA, a certification, or a claim that Atlas is free of vulnerabilities.

Supported versions

Atlas supports the current release line on main after the latest intentional version merge. Security and compatibility fixes are prioritized for that line.

Line Security fixes
Current Atlas 1.x on main Yes — prioritized
Previous supported 1.x / 0.5.0 Adjacent window only
Older 0.x snapshots Only when explicitly stated
LTS None at this stage

See Releases and governance for versioning and support policy. Do not assume older tagged snapshots receive patches.

Reporting a vulnerability

Do not disclose suspected vulnerabilities through a public GitHub issue.

Report privately using GitHub Private Vulnerability Reporting on this repository:

https://github.com/blitzcraftlabs/atlas/security/advisories/new

If that form is temporarily unavailable, contact a repository maintainer through a private channel. Do not invent or publish a security-contact email address.

Include:

  • a description of the issue and affected Atlas surfaces;
  • steps to reproduce, or a proof of concept that does not include real credentials;
  • Atlas version, commit SHA, or downstream fork baseline if known;
  • any mitigating configuration you already applied.

Internal response targets

These are internal maintainer targets, not contractual SLAs.

Severity Acknowledge / triage Remediation target (when practical)
Critical Urgently, typically within 24–48 hours ≤ 24–48 hours
High ≤ 2 business days ≤ 7 days
Moderate ≤ 5 business days ≤ 30 days
Low Planned according to risk and release cycle Next suitable release

Severity for dependency findings follows the Atlas vulnerability policy (security/policy.json): HIGH and CRITICAL block CI unless a machine-readable, time-limited exception is in force.

Downstream propagation

Atlas security fixes land on main, then ship to downstream Atlas consumers through the existing upgrade and fix-propagation machinery — not as an independent npm security product.

See:

Typical path:

security fix → Atlas main → versioned Atlas snapshot / migration notes → consumer upgrade

Auth session code and lib/security/** are high-scrutiny synced surfaces. Customized consumer copies are merge-required during upgrades.

Automated scanning on this repository

Keep Atlas CI distinct from GitHub-native products:

  • Atlas-owned merge gates — Secrets Scan (Gitleaks) and Security Audit (pnpm security:check) are required status checks on main, with Governance, CI, and UI Quality.
  • GitHub CodeQL code scanning — default setup is enabled on blitzcraftlabs/atlas. It is not a required merge gate and is not a substitute for private vulnerability reports.
  • GitHub Code Quality — a separate GitHub maintainability product; not currently configured.

Those GitHub-native settings are not packaged into generated Atlas consumers. See security engineering.

Related documents

There aren't any published security advisories