Security fixes apply only to the latest published version of each @commissary/* package. The project does not maintain security fixes for older 0.x versions.
Do not open a public issue, discussion, or pull request for a suspected vulnerability.
Use one of these private channels:
- Report a vulnerability through GitHub.
- Email security@spiritledsoftware.com if GitHub private reporting is not available.
Include:
- The affected package and version.
- A clear description of the problem and its impact.
- Steps or code that reproduce the problem.
- Any known workaround.
- Your preferred contact details.
Never include real credentials, private data, or harmful production payloads.
Spirit-Led Software LLC will confirm receipt within five business days. We will investigate, give status updates when useful, and coordinate disclosure with the reporter. We will not promise a repair date before we understand the problem and its impact.
Please keep the report private until a fix or mitigation is available and a disclosure date is agreed.