Security
Supported versions and how to report a vulnerability
Supported versions
Only the latest published vern-llm version on npm receives security fixes. Please upgrade to the latest release before reporting an issue.
Reporting a vulnerability
Please do not open a public GitHub issue for security vulnerabilities.
Instead, report it privately using GitHub's private vulnerability reporting for this repository. If that's unavailable to you, open a draft security advisory or contact the maintainer directly through GitHub.
Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce, or a minimal repro if possible
- The affected version(s)
You should expect an initial response within a few days. Once a fix is confirmed, we'll coordinate on disclosure timing and credit (if you'd like it) before a public advisory is published.
Scope
This policy covers the vern-llm package itself (packages/vern-llm). Vulnerabilities in third-party dependencies should be reported upstream, though we're happy to hear about them too if they affect this project.