We take the security of our templates, libraries, and applications very seriously. This document outlines how to report vulnerabilities and defines supported versions.
Only the latest major version of this template receives active security patches.
| Version | Supported |
|---|---|
| 1.x | ✅ Yes |
| < 1.0 | ❌ No |
We recommend pulling updates from the template master branch periodically to adopt dependencies updates and security patches.
Please do not open a public GitHub issue for security-sensitive bugs.
If you discover a security vulnerability in this project, please report it privately:
- Email Support: Send an email to
security@your-domain.comdetailing the vulnerability. - GitHub Private Disclosure: If private reporting is enabled on this repository, navigate to the Security tab and click Report a vulnerability under "Advisories".
To help us evaluate and patch the issue, please include:
- A description of the vulnerability and its potential impact.
- Step-by-step reproduction instructions (ideally with code snippets or a proof of concept).
- Details on the operating system, Node version, and browser/devices tested on.
We will acknowledge receipt of your report within 48 hours and provide a patch or mitigation plan within 10 business days, keeping you updated throughout the process.