Security fixes are provided for the latest release in the current major version line.
| Version | Supported |
|---|---|
| 1.x | ✅ |
| < 1.0 | ❌ |
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
If you believe you have found a security issue in Regle or any of its published packages (@regle/core, @regle/rules, @regle/schemas, @regle/nuxt, @regle/mcp-server, etc.), report it privately so we can investigate and coordinate a fix before public disclosure.
Use GitHub Private Vulnerability Reporting for this repository.
If you cannot use that form, contact the maintainer through a private channel (for example, a direct message to @victorgarciaesgi) and ask for a secure way to share details.
To help us reproduce and assess the issue quickly, please include:
- A clear description of the vulnerability and its potential impact
- Steps to reproduce, or a minimal proof of concept when possible
- Affected package(s) and version(s)
- Any relevant configuration, environment details, or mitigations you are aware of
- Acknowledgement: We aim to confirm receipt within 5 business days.
- Updates: We will keep you informed of our progress as we investigate.
- Disclosure: We prefer coordinated disclosure. Please allow reasonable time for a fix before public disclosure. We will work with you on timing and credit for valid reports when appropriate.
- Safe harbor: Good-faith security research that follows this policy will not be met with legal action from the project maintainers.
This repository uses automated security tooling, including CodeQL analysis and OpenSSF Scorecard, to help detect issues early. Security reports from the community remain essential for catching problems that automated checks may miss.
Thank you for helping keep Regle and its users safe.