Skip to content

Security: tabler/unstroke

SECURITY.md

Security Policy

We take security seriously and appreciate responsible disclosure of vulnerabilities.

Supported versions

Version Supported
1.x ✅
0.x ❌

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues.

If you think you have found a security issue, report it privately in one of two ways:

Please include:

  • A descriptive title
  • A description of the issue and its potential impact
  • Steps to reproduce, or a proof of concept if possible
  • The affected version(s)

We will review your report and get back to you as soon as possible. Please give us reasonable time to address the issue before disclosing it publicly.

Scope

unstroke parses untrusted SVG. Input that makes the parser or the geometry pipeline hang, allocate without bound or crash the process is in scope, as is anything that lets crafted input write outside the requested output location when using the CLI.

There aren't any published security advisories