Skip to content

Security: pilgrimagesoftware/dtrpg-sdk.js

SECURITY.md

Security Policy

Supported Versions

This package is pre-1.0. Only the latest version published on npm receives security fixes. Please upgrade before reporting an issue to confirm it still reproduces.

Reporting a Vulnerability

Do not open a public issue for security vulnerabilities.

Report privately via GitHub's Security Advisories. This keeps the report confidential until a fix is released.

Include, where possible:

  • Affected version(s)
  • A minimal reproduction or proof of concept
  • Impact (e.g. what an attacker can do, what data or systems are exposed)

You should receive an initial response as soon as possible. If the report is confirmed, we'll work with you on a fix and coordinate a disclosure timeline before any public advisory is published. Reporters are credited in the advisory unless they ask to remain anonymous.

Scope

This policy covers the dtrpg-sdk.js package and its published GitHub Actions workflows. Vulnerabilities in dependencies should be reported upstream; if a dependency issue affects this package directly (e.g. no available patched version), open a private advisory here as well so we can track mitigation. CI runs npm audit --audit-level=high on every build to catch known advisories in dependencies.

There aren't any published security advisories