We support the latest minor version of create-cartwright published to npm. Older versions receive security fixes only for critical CVEs.
Do not open public GitHub issues for security vulnerabilities.
Instead, email security@cartwright.app with:
- Description of the vulnerability
- Steps to reproduce
- Affected versions
- Any proposed mitigation
We aim to respond within 48 hours and patch critical issues within 7 days.
After a fix is released and users have had reasonable time to upgrade (typically 2 weeks), we publish a security advisory via GitHub Security Advisories with full details.
In-scope:
create-cartwrightnpm package- cartwright.app site
- Public
cartwright-templatemirror
Out-of-scope (private repo, separate disclosure):
- The cartwright template itself — see private repo's SECURITY.md