We take the security of the Gea ecosystem seriously. This document outlines how to report vulnerabilities and our policy regarding security updates.
As this is an open-source project maintained in spare time, security responses and updates are handled on a best-effort basis.
We primarily focus security updates on the latest major version of each package.
| Package | Version | Supported |
|---|---|---|
gea-a11y |
1.x | ✅ Yes |
gea-query |
1.x | ✅ Yes |
gea-form |
1.x | ✅ Yes |
Please do not report security vulnerabilities via public GitHub Issues.
If you discover a potential security vulnerability within any package in this project, please report it responsibly via GitHub Private Vulnerability Reporting or by contacting the maintainer:
- Contact: GeaStack Community
When reporting a vulnerability, please provide:
- The specific package(s) affected.
- A description of the vulnerability and its potential impact.
- Steps to reproduce or a minimal working example.
- Any details regarding the environment (Node.js version, browser, OS) where the issue occurs.
While strict response timelines cannot be guaranteed, we aim to handle reports as follows:
- Acknowledgment: We will try to acknowledge your report as soon as reasonably possible.
- Investigation: We will investigate the issue when time and resources allow.
- Fix & Release: Once verified, a patch will be released and, if desired, you will be credited for the discovery.