Skip to content

Security: aquie00tt/express-typescript-starter-kit

.github/SECURITY.md

Security Policy

Supported Versions

This section informs users about which versions of the project are currently supported with security updates.

Version Supported
1.1.x
1.0.x

Reporting a Vulnerability

If you discover a security vulnerability within this project, please report it immediately by contacting us via email at [[email protected]].

Here’s how to report vulnerabilities:

  1. Email: Send us an email detailing the vulnerability and its potential impact. Include steps to reproduce the issue if possible.
  2. Response Time: We aim to respond to all vulnerability reports within 48 hours.
  3. Updates: You can expect regular updates on the status of your report until it is resolved.
  4. Acceptance or Decline: Once we have reviewed the report, we will inform you whether the vulnerability has been accepted for a fix or if further information is needed.

Confidentiality

Please ensure that all vulnerability details are kept confidential until a fix has been released. This helps protect our users and prevents potential exploitation.

Security Updates

We recommend keeping your version of the project up-to-date to ensure you receive the latest security updates. Check our Releases page for the latest updates.

Acknowledgements

If your report leads to a security fix, we will be happy to acknowledge your contribution in our release notes (unless you prefer to remain anonymous).

There aren’t any published security advisories