We take the security of SentientUI and its users seriously. Thank you for helping keep the project and its community safe.
Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.
Use one of these private channels instead:
- GitHub private vulnerability reporting — the Report a vulnerability button under this repository's Security tab (preferred), or
- Email security@sentient-ui.com.
If possible, include:
- A description of the vulnerability and its potential impact
- Steps to reproduce (proof-of-concept, affected package/endpoint, versions)
- Any suggested remediation
You can expect an acknowledgement within a few business days. We'll keep you informed as we investigate and coordinate a disclosure timeline with you.
This policy covers the code in this repository — the published @sentientui/* client packages
— as well as the hosted SentientUI API and dashboard they talk to.
Security fixes are applied to the latest released version of each published package. We recommend always running the most recent version.
Please give us a reasonable amount of time to release a fix before any public disclosure, and avoid accessing or modifying other users' data while researching an issue. We're happy to credit reporters who follow this process.