Skip to content

Security: superdoc/docx-editor

SECURITY.md

Security Policy

Supported Versions

We actively support both the 2.x and 1.x release lines. Security fixes land in the latest patch release of each line, so upgrading within your major version is enough to receive them.

Release line npm dist-tag Supported
2.x latest ✅ Supported
1.x legacy ✅ Supported
Pre-releases next ⚠️ Best effort, not for production

Versions below 1.0 are no longer supported.

Reporting a Vulnerability

If you believe you’ve found a security issue in SuperDoc, please do not open a public GitHub issue.

Instead, report it privately through GitHub’s Security Advisories.

This ensures the report is only visible to maintainers.

If you prefer email, you can also contact us at: q@superdoc.dev

Our Process

  • We will acknowledge receipt within 2 business days.
  • We will provide a status update within 7 days.
  • Once a fix is available, we’ll coordinate a responsible disclosure with you.

Thank you for helping keep SuperDoc and its users safe!

There aren't any published security advisories