Skip to content

Security: Qeloma/.github

Security

SECURITY.md

Security Policy

Supported Versions

Qeloma apps and libraries are actively maintained on their latest published release. Security fixes are made against the latest version; older versions are not patched.

Package / App Supported
Latest release of any @qeloma/* package Yes
Latest deployed version of any Qeloma app Yes
Older, unpublished, or archived versions No

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Instead, report it privately by emailing security@qeloma.dev (placeholder — update to a monitored inbox before relying on this policy), or via GitHub Security Advisories on the affected repository if enabled.

Please include:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce, or a proof of concept
  • The affected package/app and version

What to Expect

  • Acknowledgement of your report within a reasonable timeframe
  • An assessment of severity and, if confirmed, a plan for a fix
  • Credit in the fix's release notes, if you'd like it, once the issue is resolved

Disclosure

We ask that you give us the opportunity to investigate and address a reported vulnerability before any public disclosure.

There aren't any published security advisories