Skip to content

Security: Timonwa/react-chat

Security

SECURITY.md

Security Policy

Thanks for helping keep this project and its users safe.

Supported versions

Security fixes are applied to the latest version — the newest commit on main for apps, the latest published version for packages. Older commits and versions are not patched.

Reporting a vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Preferred: GitHub Security Advisories

Use the repository's Security tab → Report a vulnerability. This opens a private channel between you and the maintainer — nothing you submit is publicly visible until we publish the advisory together after a fix ships.

Fallback: email

me[@]timonwa[dot]com

Please include:

  • A clear description of the issue and its impact
  • Steps to reproduce (including the version, commit, or deployed URL you tested against)
  • Any proof-of-concept code or logs, if relevant
  • Whether you'd like to be credited in the fix announcement

What to expect

  • Acknowledgment within 72 hours of your report reaching me.
  • Initial triage within 7 days — I'll let you know whether the report is accepted, declined, or needs more detail.
  • Fix timeline depends on severity. Critical issues (data leakage, auth bypass, RCE) are prioritised immediately; lower-severity issues may take longer.
  • Credit. Reporters of accepted vulnerabilities get credit in the release notes and advisory, unless you prefer to remain anonymous.
  • Coordinated disclosure. Please give me a reasonable window to ship a fix before publishing details. 90 days is a common baseline; I'll aim faster for anything serious.

Out of scope

  • Vulnerabilities in third-party services a project depends on — please report those directly to the respective vendors
  • Missing best-practice HTTP headers with no concrete impact
  • Findings from automated scanners without a reproducible exploit

A repository with its own SECURITY.md overrides this default and may define a more specific scope.

There aren't any published security advisories