Skip to content

Security: khacnamdev/typescript-engineering-template

Security

SECURITY.md

Security Policy

We take the security of our templates, libraries, and applications very seriously. This document outlines how to report vulnerabilities and defines supported versions.


🛡️ Supported Versions

Only the latest major version of this template receives active security patches.

Version Supported
1.x ✅ Yes
< 1.0 ❌ No

We recommend pulling updates from the template master branch periodically to adopt dependencies updates and security patches.


🔒 Reporting a Vulnerability

Please do not open a public GitHub issue for security-sensitive bugs.

If you discover a security vulnerability in this project, please report it privately:

  1. Email Support: Send an email to security@your-domain.com detailing the vulnerability.
  2. GitHub Private Disclosure: If private reporting is enabled on this repository, navigate to the Security tab and click Report a vulnerability under "Advisories".

What to Include in a Report

To help us evaluate and patch the issue, please include:

  • A description of the vulnerability and its potential impact.
  • Step-by-step reproduction instructions (ideally with code snippets or a proof of concept).
  • Details on the operating system, Node version, and browser/devices tested on.

Response Timeline

We will acknowledge receipt of your report within 48 hours and provide a patch or mitigation plan within 10 business days, keeping you updated throughout the process.

There aren't any published security advisories