Skip to content

Security: magdy-abas/ngx-otp-inputs

Security

SECURITY.md

Security Policy

Supported Versions

We only provide security updates for the latest major version of ngx-otp-inputs.
Please update to the most recent release before submitting a security report.

Version Supported
latest
< latest

Reporting a Vulnerability

If you discover a security vulnerability in ngx-otp-inputs, please help us by reporting it privately.
Do not create a public GitHub issue for security problems.

How to report

Send an email to:

magdyabas40@gmail.com

Please include:

  • A detailed description of the vulnerability.
  • Steps to reproduce it.
  • Any possible fixes or workarounds.

Response Time

We aim to:

  • Acknowledge your report within 48 hours.
  • Provide a status update within 5 working days.
  • Release a fix as soon as possible, depending on complexity.

Scope

Security issues include (but are not limited to):

  • Remote Code Execution (RCE)
  • Cross-Site Scripting (XSS)
  • Data leaks or exposure of sensitive information
  • Unauthorized access or privilege escalation

The following are not considered security issues:

  • General bugs or crashes (please report via GitHub Issues)
  • Feature requests
  • Compatibility issues with unsupported browsers or Angular versions

Disclosure Policy

We kindly request that you:

  1. Report the issue privately first.
  2. Allow us reasonable time to investigate and release a fix.
  3. Avoid publicly disclosing details until the fix has been released.

Thank you for helping keep ngx-otp-inputs and its users safe.

There aren’t any published security advisories