Skip to content

Security: Teloz1870/cartwright-app

Security

SECURITY.md

Security Policy

Supported versions

We support the latest minor version of create-cartwright published to npm. Older versions receive security fixes only for critical CVEs.

Reporting a vulnerability

Do not open public GitHub issues for security vulnerabilities.

Instead, email security@cartwright.app with:

  • Description of the vulnerability
  • Steps to reproduce
  • Affected versions
  • Any proposed mitigation

We aim to respond within 48 hours and patch critical issues within 7 days.

Disclosure policy

After a fix is released and users have had reasonable time to upgrade (typically 2 weeks), we publish a security advisory via GitHub Security Advisories with full details.

Scope

In-scope:

  • create-cartwright npm package
  • cartwright.app site
  • Public cartwright-template mirror

Out-of-scope (private repo, separate disclosure):

  • The cartwright template itself — see private repo's SECURITY.md

There aren't any published security advisories