Skip to content

Security: clywell/filter-toolbar

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.x.x

Reporting a Vulnerability

The security of our software is important to us. If you discover a security vulnerability, please follow these guidelines:

How to Report

  1. Do NOT open a public issue for security vulnerabilities
  2. Email us directly at security@clywell.com
  3. Include detailed information about the vulnerability:
    • Description of the vulnerability
    • Steps to reproduce the issue
    • Potential impact
    • Any suggested fixes

What to Expect

  • Initial response: Within 48 hours
  • Status update: Within 7 days with either a resolution timeline or request for additional information
  • Resolution: We aim to resolve critical vulnerabilities within 30 days

Disclosure Policy

  • We will coordinate with you on the disclosure timeline
  • We will credit you in the security advisory (unless you prefer to remain anonymous)
  • We follow responsible disclosure practices

Security Considerations

This package primarily handles UI state and doesn't process sensitive data directly. However, we take security seriously for:

  • Dependencies: Regular updates and vulnerability scanning
  • Build process: Secure CI/CD pipeline
  • Package integrity: Signed releases and checksums

Bug Bounty

We currently do not offer a bug bounty program, but we greatly appreciate responsible disclosure of security issues.

Contact

For security-related questions or concerns:

There aren’t any published security advisories