Skip to content

Security: mdbase-dev/mdbase-writer

SECURITY.md

Security policy

mdbase writer is prerelease software.

Reporting a vulnerability

Please do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting for this repository. Include:

  • the affected component (web app, compile worker, export) and version or commit;
  • the prerequisites and smallest reproducible sequence;
  • the impact you observed or believe is possible; and
  • relevant logs or artifacts with credentials, collection paths, and manuscript text removed.

Do not access data that is not yours, degrade a service, or publish details before a coordinated disclosure date. Response times are goals rather than a service-level agreement while the project is maintained by a small team.

Supported versions

Only the current main branch and the deployed site receive fixes.

There aren't any published security advisories