Skip to content

Security: wornpage/scenarios

SECURITY.md

Security policy

Supported surface

Security fixes target the latest default-branch revision and the latest published release of each Wornpage repository. Older revisions may be fixed only when a current consumer still depends on them.

Report a vulnerability privately

Use Security → Report a vulnerability in the affected GitHub repository. Private vulnerability reporting is enabled across the public Wornpage repositories.

Include the affected repository and revision, realistic impact, required preconditions, and the smallest reproducible example. Do not place credentials, private source, personal data, or an active exploit in a public issue.

Use ordinary GitHub issues for defects that do not cross a security or privacy boundary.

Disclosure

Please allow time to confirm the report, prepare a bounded fix, and update affected immutable source pins before public disclosure. Wornpage will keep the report private while that work is in progress.

There aren't any published security advisories