Skip to content

Security: hraness/vercel-delivery

SECURITY.md

Security

Report vulnerabilities privately through the repository's GitHub security advisory page. Do not open a public issue for an undisclosed vulnerability.

The delivery-proof token is deterministic public deployment metadata, not a secret, signature, or authentication credential. Preview-origin environment values are display evidence only. Applications must make authorization and routing decisions from trusted server-side state.

Security fixes are supported on the latest release. Include affected versions, reproduction conditions, and impact in a report. Do not include live credentials or private deployment data.

There aren't any published security advisories