Qeloma apps and libraries are actively maintained on their latest published release. Security fixes are made against the latest version; older versions are not patched.
| Package / App | Supported |
|---|---|
Latest release of any @qeloma/* package |
Yes |
| Latest deployed version of any Qeloma app | Yes |
| Older, unpublished, or archived versions | No |
Do not open a public GitHub issue for security vulnerabilities.
Instead, report it privately by emailing security@qeloma.dev (placeholder — update to a monitored inbox before relying on this policy), or via GitHub Security Advisories on the affected repository if enabled.
Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce, or a proof of concept
- The affected package/app and version
- Acknowledgement of your report within a reasonable timeframe
- An assessment of severity and, if confirmed, a plan for a fix
- Credit in the fix's release notes, if you'd like it, once the issue is resolved
We ask that you give us the opportunity to investigate and address a reported vulnerability before any public disclosure.