Skip to content

Security: kim1124/comins-layout

SECURITY.md

Security Policy

Reporting a Vulnerability

Report potential vulnerabilities privately through this repository's GitHub Security Advisories page using Private Vulnerability Reporting. Do not open a public issue, pull request, or discussion for an unpatched vulnerability.

Supported Versions

Before 1.0.0, only the latest published version receives security fixes.

Latest verified published version: 0.2.3. The support table follows verified npm publication, not source version changes alone.

Version Supported
0.2.3 Yes
< 0.2.3 No

Before a Public npm Release

Keep Private Vulnerability Reporting active and enable GitHub's available dependency and secret-scanning alerts. Bootstrap the brand-new npm package interactively with maintainer 2FA and no automation token because trusted and staged publishing require an existing package.

After bootstrap, register the exact repository, publish.yml, and npm environment as the trusted publisher. Allow only npm stage publish, disallow token publishing, and require maintainer 2FA approval for every staged version.

Disclosure

The maintainer will assess the report, prepare a remediation when applicable, and decide whether to publish a GitHub security advisory or request a CVE after the remediation is available.

Credential and PII Incidents

Treat a credential/PII incident as a release blocker. Stop the affected release, rotate any exposed credential, preserve non-public evidence, and coordinate remediation without public disclosure of the sensitive value.

There aren't any published security advisories