This policy applies to all published SDK packages in this repository:
@supashiphq/javascript-sdk@supashiphq/react-sdk@supashiphq/vue-sdk
Please report vulnerabilities privately:
- Email:
security@supaship.com - Subject:
Security report - Supaship SDK - Include: affected package, version, impact, and reproduction details
Do not open public issues for suspected vulnerabilities.
After acknowledgement, we will:
- Validate and triage the report
- Prepare and test a fix
- Publish patched versions
- Share a public advisory after remediation