Skip to content

Security: 0xWDG/spm

Security

SECURITY.md

Security policy

Supported versions

spm is currently pre-1.0. Security fixes are applied to the latest code on the main branch. Older revisions are not maintained separately.

Report a vulnerability

Do not disclose a suspected vulnerability in a public issue, discussion, or pull request.

Use GitHub's private vulnerability reporting when it is available. Otherwise, email email@WesleydeGroot.nl with:

  • the affected command or component;
  • steps to reproduce the issue;
  • its potential impact;
  • any suggested mitigation; and
  • whether the report has been shared elsewhere.

Avoid including real credentials or sensitive user data. You will receive an acknowledgement after the report has been reviewed, followed by updates when there is meaningful progress to share.

There aren't any published security advisories