Spindle is pre-1.0 and under active development. Security fixes are applied to
the latest published release of each @weavertime/spindle-* package. Please
make sure you are on the most recent version before reporting an issue.
Please do not open a public GitHub issue for security vulnerabilities.
Instead, report privately through either of:
- GitHub's private vulnerability reporting (Security → Report a vulnerability), or
- email hello@bharatnadkarni.com with the subject line
SECURITY: Spindle.
Please include:
- the affected package(s) and version(s),
- a description of the issue and its impact,
- and a minimal reproduction or proof of concept if possible.
- We aim to acknowledge your report within 5 business days.
- We will keep you updated as we investigate and work on a fix.
- Once a fix is released, we are happy to credit you in the release notes unless you prefer to remain anonymous.
Thank you for helping keep Spindle and its users safe.