Skip to content

Security: null-jj/FrameKit

SECURITY.md

Security Policy

Supported Versions

Until Framekit reaches 1.0, security fixes are provided for the latest published 0.x minor release only. After 1.0, the current major release and the immediately preceding major release will receive security fixes for at least twelve months after supersession.

Reporting A Vulnerability

Do not open a public issue for suspected vulnerabilities. Use the repository's Security → Report a vulnerability flow to submit a private GitHub Security Advisory. Include the affected package and version, reproduction steps, impact, and any suggested mitigation. Do not include live credentials or customer data.

Maintainers target acknowledgement within three business days and an initial severity assessment within seven business days. Remediation and disclosure timing depend on severity and ecosystem coordination; these targets are not a service-level agreement.

Disclosure

Maintainers coordinate fixes, package publication, advisories, and credit with the reporter. Please allow a reasonable remediation window before public disclosure.

There aren't any published security advisories