| Version | Supported |
|---|---|
| 0.0.x | ✅ |
We take security seriously. If you discover a security vulnerability, please follow these steps:
- Open a public GitHub issue
- Discuss the vulnerability publicly before it's fixed
-
Email us directly at security@philjs.dev with:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fixes
-
Allow time for response - We aim to respond within 48 hours
-
Coordinate disclosure - We'll work with you to understand and fix the issue before any public disclosure
- Acknowledgment - We'll confirm receipt of your report within 48 hours
- Assessment - We'll investigate and determine the severity
- Fix - We'll develop and test a fix
- Release - We'll release the fix and credit you (if desired)
- Disclosure - We'll publish a security advisory
This policy applies to:
- All packages in the philjs monorepo
- Official PhilJS documentation site
- Official PhilJS examples
We appreciate security researchers who help keep PhilJS safe. With your permission, we'll acknowledge your contribution in:
- Release notes
- Security advisories
- Our contributors list
Thank you for helping keep PhilJS and its users safe!