Skip to content

Security: ktjn/searchable

SECURITY.md

Security policy

Searchable's npm and Python packages are not yet published. Security reports may still affect the source repository, generated indexes, browser runtime, or live documentation.

Reporting a vulnerability

Once the repository is public, use GitHub's private vulnerability reporting:

  1. Open the repository's Security tab.
  2. Select Report a vulnerability.
  3. Include affected code or versions, impact, reproduction steps, and any suggested mitigation.

Do not open a public issue, discussion, or pull request for a suspected vulnerability. If the private reporting button is unavailable, wait for the maintainer to enable it rather than disclosing the report publicly.

The maintainer will acknowledge the report, investigate it privately, and coordinate remediation and disclosure according to severity. No fixed response time is promised while the project is maintained by a single person.

Supported versions

There is no released registry version yet. Security fixes currently target the latest commit on main; a released-version support table will be added with the first package publication.

There aren't any published security advisories