Skip to content

Security: artvandervennet/artui

Security

SECURITY.md

Security policy

Reporting a vulnerability

Please do not open a public issue for security problems. Instead, use GitHub's private reporting:

  1. Go to the Security tab on this repository.
  2. Click Report a vulnerability.
  3. Describe the issue, the affected package, and a reproduction if possible.

You can expect:

  • An acknowledgement within 5 business days.
  • A coordinated fix and disclosure plan for confirmed issues.
  • Credit in the release notes once a fix ships, if you would like that.

Supported versions

Only the most recent minor version of the published @artui/cli package receives fixes. The hosted MCP server at artui.vandervennet.art/api/mcp is updated continuously alongside the docs site. The @artui/registry components themselves are copy-pasted into consumer projects, so once copied they are owned by that project — fixes are published as updated component sources that the CLI can re-fetch.

There aren't any published security advisories