Security fixes are released for the latest major version only.
| Version | Supported |
|---|---|
| 2.x | ✅ Yes |
| < 2.0 | ❌ No |
Please do not open a public issue for security vulnerabilities.
Report privately through GitHub: Security → Advisories → Report a vulnerability.
Include a description, steps to reproduce, the affected version, and the potential impact. A suggested fix is welcome but not required.
- Acknowledgement within 3 business days
- An initial assessment within 7 days
- A fix and coordinated disclosure through a GitHub Security Advisory, with credit to the reporter if they wish
move-prop-types rewrites JavaScript and TypeScript source files in place.
- It only writes regular files inside the path given with
-Por the folder given with-F. Symbolic links found while walking a folder are skipped and reported, never followed. -Irunspnpm add prop-typesin the current directory. No user input is passed to the shell.- Commit or back up your code first and review the diff before committing the result.
- Releases are published from GitHub Actions through
npm trusted publishing with
provenance. Verify with
npm audit signatures. - Dependabot keeps npm dependencies and GitHub Actions up to date; pull requests go through dependency review and CodeQL code scanning.
- GitHub Actions are pinned to commit SHAs, and workflow tokens are read-only by default.
- Dependency install scripts do not run unless explicitly allowed in
pnpm-workspace.yaml.