Searchable's npm and Python packages are not yet published. Security reports may still affect the source repository, generated indexes, browser runtime, or live documentation.
Once the repository is public, use GitHub's private vulnerability reporting:
- Open the repository's Security tab.
- Select Report a vulnerability.
- Include affected code or versions, impact, reproduction steps, and any suggested mitigation.
Do not open a public issue, discussion, or pull request for a suspected vulnerability. If the private reporting button is unavailable, wait for the maintainer to enable it rather than disclosing the report publicly.
The maintainer will acknowledge the report, investigate it privately, and coordinate remediation and disclosure according to severity. No fixed response time is promised while the project is maintained by a single person.
There is no released registry version yet. Security fixes currently target the
latest commit on main; a released-version support table will be added with the
first package publication.