Skip to content

Security: minislively/wasm-first-workflow-editor

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security issue, please do not open a public GitHub issue first.

Instead, report it privately through GitHub Security Advisories or the maintainer contact path chosen for this repository.

What to include

Please include:

  • affected package or app
  • reproduction steps
  • impact
  • suggested mitigation, if known

Scope

Security-sensitive areas may include:

  • runtime event contracts
  • worker/runtime boundaries
  • Web Component embedding surfaces
  • WASM loading and fallback behavior
  • host-controlled graph/document input paths

Response expectations

We will try to:

  • acknowledge the report
  • assess severity
  • provide a fix or mitigation path
  • disclose publicly only after a fix or safe mitigation is available

There aren’t any published security advisories