Sitelet https://github.com/recomposesh/recompose/security
Skip to content

Security: recomposesh/recompose

SECURITY.md

Security policy

Reporting a vulnerability

Report a security vulnerability through GitHub's private vulnerability reporting on this repository. Don't file a public issue or pull request for a security concern. That would expose it before a fix ships.

Supported versions

recompose is pre-release software with no tagged releases yet. The only supported version is the latest commit on main. Older commits don't receive security fixes.

What to expect

The maintainer aims to acknowledge a new report within five business days. Confirmation of the issue and an initial severity assessment follow within two weeks. Public disclosure waits until a fix ships, or ninety days after the report, whichever comes first, unless you and the maintainer agree on a different timeline.

There aren't any published security advisories