| Version | Supported |
|---|---|
main (pre-1.0) |
Yes |
| unpublished packages | Yes — report before publish |
Pulse is early. Treat every release as potentially breaking until 1.0.
Do not open a public issue for security vulnerabilities.
Email codeforstartups@gmail.com with:
- A description of the issue
- Steps to reproduce
- Impact assessment
- Any suggested fix (optional)
You should receive an acknowledgement within 72 hours.
We will:
- Confirm the issue and severity
- Work on a fix privately when needed
- Credit you in the advisory if you want attribution
In scope:
- The
@pulse/*packages in this repository - The official website build in
website/ - CI / release pipelines that could leak secrets
Out of scope:
- Third-party provider plugins not maintained here
- Issues that require physical access or social engineering
- Denial of service against public GitHub infrastructure
We prefer coordinated disclosure. Please give us a reasonable window to patch before public write-ups.