Skip to content

Security: Trade-su/SitePing

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
latest
< latest

Only the latest published version of each @siteping/* package receives security updates.

Reporting a Vulnerability

Do not open a public issue for security vulnerabilities.

Instead, please report vulnerabilities through one of these channels:

  1. GitHub Security Advisories (preferred) -- Report a vulnerability
  2. Email -- Send details to security@neosianexus.dev

What to include

  • Description of the vulnerability
  • Steps to reproduce
  • Affected package(s) and version(s)
  • Potential impact

Response Timeline

Step Timeline
Acknowledgment Within 48 hours
Initial assessment Within 1 week
Fix release Within 30 days (critical), 90 days (non-critical)

Disclosure Policy

  • We follow coordinated disclosure.
  • We will credit reporters in the release notes (unless you prefer to remain anonymous).
  • We ask that you do not publicly disclose the vulnerability until a fix has been released.

Scope

This policy applies to all packages in the @siteping/* scope:

  • @siteping/widget
  • @siteping/adapter-prisma
  • @siteping/adapter-memory
  • @siteping/adapter-localstorage
  • @siteping/cli

There aren't any published security advisories