Skip to content

Security: zemd/tooling

SECURITY.md

Security policy

Security fixes are provided only for the latest released version of each public package and the latest Marketplace release of each Visual Studio Code extension in this repository. Older releases are not supported.

Reporting a vulnerability

Do not report vulnerabilities through public issues, pull requests, or discussions.

Use one of these private channels:

  1. GitHub Private Vulnerability Reporting (preferred).
  2. Email oss@zemd.dev with the subject SECURITY: <package name>.

Include the affected package and version, impact, environment, reproduction steps, and any known mitigations. The maintainers aim to acknowledge complete reports within two business days and provide an initial assessment within seven business days.

Scope and disclosure

The source, workflows, npm packages, and Visual Studio Code extensions maintained in this repository are in scope. Findings that affect only a third-party dependency, automated scanner output without demonstrated impact, denial-of-service testing, social engineering, and attacks against third-party services are out of scope.

Keep vulnerability details private until a fix and advisory are published or 90 days have elapsed, whichever comes first. Good-faith research that follows this policy and avoids privacy violations, service disruption, data destruction, persistence, and unnecessary access will be considered authorized by the maintainers.

This volunteer-maintained project does not operate a bug bounty program.

There aren't any published security advisories