Skip to content

Security: mikinho/node-autover

Security

SECURITY.md

Security Policy

Supported versions

Security fixes are provided for the latest published release on supported Node.js release lines. The package requires Node.js 22.13.0 or newer; the exact minimum and Node.js 24 are exercised in CI.

Reporting a vulnerability

Please report suspected vulnerabilities privately through this repository's GitHub Security Advisory form. If private vulnerability reporting is unavailable, email me@mikinho.com with the repository name and "security" in the subject. Do not open a public issue before a fix or disclosure plan is agreed.

Include the affected version, impact, reproduction steps, and any suggested mitigation. Reports are normally acknowledged within three business days and triaged within seven business days. Timelines for a fix and coordinated disclosure depend on severity, exploitability, and release complexity.

Coordinated disclosure and safe harbor

Please allow reasonable time for investigation and remediation before public disclosure. Good-faith research that avoids privacy violations, service disruption, data destruction, persistence, and access beyond what is necessary to demonstrate the issue will not be pursued by the maintainer.

There aren't any published security advisories