Skip to content

Security: rcpthongta/string-utils

SECURITY.md

Security Policy

Supported Versions

Security updates are currently provided for the latest published version of @rcpthongta/string-utils.

Version Supported
Latest ✅
Older versions ❌

Reporting a Vulnerability

If you discover a security vulnerability in @rcpthongta/string-utils, please report it privately.

Please do not report security vulnerabilities through public GitHub issues.

To report a vulnerability, please use GitHub Private Vulnerability Reporting.

When reporting a vulnerability, please include:

  • A clear description of the vulnerability
  • The affected version
  • Steps to reproduce the issue
  • A minimal proof of concept, if applicable
  • Any potential impact or attack scenario

You may redact or omit sensitive information that is not necessary to reproduce the issue.

Response Process

After receiving a vulnerability report, we will:

  1. Review and validate the report.
  2. Assess the severity and potential impact.
  3. Work on a fix or mitigation when necessary.
  4. Release a patched version when appropriate.
  5. Credit the reporter, with their permission.

We aim to handle security reports responsibly and keep affected users informed when a security issue is confirmed.

Scope

This security policy applies to:

  • The source code of @rcpthongta/string-utils
  • Published packages distributed through npm
  • Public APIs and functionality provided by the package

Issues that are not security vulnerabilities, including general bugs, feature requests, documentation issues, and usage questions, should be reported through the project's regular GitHub issue tracker.

Disclosure

Please allow reasonable time for investigation and remediation before publicly disclosing a confirmed security vulnerability.

Once a security issue has been addressed, relevant details may be disclosed publicly through the project's changelog or release notes when appropriate.

Security Updates

When a security vulnerability is confirmed and requires a code change, a patched version will be released when appropriate.

Users are encouraged to keep @rcpthongta/string-utils updated to the latest published version to receive available security fixes and improvements.

There aren't any published security advisories