Skip to content

Security: Dave-London/Pare

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in any @paretools package, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

Instead, please email: hello@os4us.org

Include:

  • Which package is affected (@paretools/git, @paretools/test, etc.)
  • A description of the vulnerability
  • Steps to reproduce (if applicable)

Response Timeline

  • Acknowledgement: Within 48 hours
  • Assessment: Within 1 week
  • Fix: Depends on severity, but we aim for patches within 2 weeks for critical issues

Scope

This policy covers all packages published under the @paretools npm scope.

Security Audits

Supported Versions

Package Supported
@paretools/* >= 0.2.0 Yes

There aren’t any published security advisories