Skip to content

Security: nimjs/ui

Security

SECURITY.md

Security policy

Report suspected vulnerabilities privately through GitHub Security Advisories. Do not publish an exploit or use a public issue before maintainers can investigate. Include affected package/path, impact, reproduction, and any suggested mitigation. If the private advisory route is unavailable, use the repository maintainer contact shown on GitHub rather than posting technical details publicly.

No public npm version has been verified. During pre-release development, maintainers assess reports against main and any actually published latest version. Older snapshots and unreleased external forks have no guaranteed support window. A report about CLI filesystem writes, executable config loading, generated source, package artifacts, or release credentials may be security relevant.

Acknowledgment, fixes, and disclosure timing depend on maintainer availability and severity; there is no fixed SLA. Maintainers may ask for validation details and coordinate release notes or disclosure after a fix. Never include secrets in a report or pull request.

There aren't any published security advisories