| Version | Supported |
|---|---|
| 0.1.x | ✅ |
If you discover a security vulnerability within React NIS2 Guard, please follow these steps:
- Do NOT create a public GitHub issue
- Email the security team at: fabrizio.di.priamo@gmail.com
- Include in your report:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment: Within 48 hours
- Initial Assessment: Within 7 days
- Resolution Target: Within 30 days (depending on severity)
When using this library:
- Always use HTTPS for the
auditEndpoint - Validate backend responses - don't trust client-side security alone
- Keep dependencies updated - run
npm auditregularly - Use Content Security Policy headers in your application
This security policy covers:
- The
@nis2shield/react-guardnpm package - Security issues in the library code itself
Out of scope:
- Issues in your application code
- Third-party dependencies (report to their maintainers)
We appreciate responsible disclosure and will acknowledge security researchers in our release notes (with permission).
Part of the NIS2 Shield ecosystem.