Skip to content

Security: jscraik/Design-System

SECURITY.md

Security Policy

Last updated: 2026-01-04

Doc requirements

  • Audience: Maintainers and security reviewers
  • Scope: Security posture, guidance, and required practices
  • Non-scope: Feature usage or product marketing
  • Owner: TBD (confirm)
  • Review cadence: TBD (confirm)

Supported Versions

We provide security updates for the most recent minor release line.

Version Supported
0.x (latest)
< 0.x latest

Reporting a Vulnerability

Please do not open public issues for security reports.

Preferred reporting channels:

  1. GitHub Security Advisories (if available in this repository).
  2. If advisories are not available, contact the maintainers privately.

What to include:

  • A clear description of the issue
  • Steps to reproduce
  • Impact assessment (what an attacker can do)
  • Affected versions and any known workarounds

We aim to respond within 5 business days and provide status updates as we investigate.

There aren’t any published security advisories