| Version | Supported |
|---|---|
| 1.x.x | ✅ |
If you discover a security vulnerability in MARK Method, please report it responsibly:
- Do NOT open a public GitHub issue for security vulnerabilities
- Email: Send details to the maintainer via GitHub's private vulnerability reporting
- Or: Use GitHub's Security Advisory feature
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment: Within 48 hours
- Status update: Within 7 days
- Resolution timeline: Depends on severity, typically within 30 days
This security policy covers:
- The mark-method npm package
- The CLI installation tool
- Generated configuration files
This policy does NOT cover:
- Third-party dependencies (report to those projects directly)
- User-generated content or configurations
When using MARK Method:
- Review generated files before committing to version control
- Never commit
.envfiles or API keys to your repository - Keep dependencies updated with
npm auditandnpm update
We appreciate responsible disclosure and will acknowledge security researchers who report valid vulnerabilities.