If you discover a security vulnerability in snpick
, we would appreciate your help in resolving it. Please report vulnerabilities to us by creating a private issue. We ask that you do not publicly disclose the details of any vulnerabilities until we have had the chance to address them.
We recommend always using the latest stable release of snpick
. Security fixes are prioritized for the following versions:
- Latest version (actively maintained)
- One prior version (security fixes when feasible)
We are committed to ensuring the security of snpick
. Critical vulnerabilities will be fixed as soon as possible, and minor vulnerabilities will be fixed in a timely manner. For updates and security notifications, please follow the repository's release page.
- Always ensure dependencies are up to date.
- Use recommended security configurations when deploying
snpick
in production. - Avoid running
snpick
with elevated privileges unless strictly necessary.
- Visit our repository security tab for more information on our security posture.