Skip to content

Security: geastack-community/ecosystem

Security

SECURITY.md

Security Policy

We take the security of the Gea ecosystem seriously. This document outlines how to report vulnerabilities and our policy regarding security updates.

As this is an open-source project maintained in spare time, security responses and updates are handled on a best-effort basis.

Supported Versions

We primarily focus security updates on the latest major version of each package.

Package Version Supported
gea-a11y 1.x ✅ Yes
gea-query 1.x ✅ Yes
gea-form 1.x ✅ Yes

Reporting a Vulnerability

Please do not report security vulnerabilities via public GitHub Issues.

If you discover a potential security vulnerability within any package in this project, please report it responsibly via GitHub Private Vulnerability Reporting or by contacting the maintainer:

What to Include

When reporting a vulnerability, please provide:

  • The specific package(s) affected.
  • A description of the vulnerability and its potential impact.
  • Steps to reproduce or a minimal working example.
  • Any details regarding the environment (Node.js version, browser, OS) where the issue occurs.

Our Process

While strict response timelines cannot be guaranteed, we aim to handle reports as follows:

  1. Acknowledgment: We will try to acknowledge your report as soon as reasonably possible.
  2. Investigation: We will investigate the issue when time and resources allow.
  3. Fix & Release: Once verified, a patch will be released and, if desired, you will be credited for the discovery.

There aren't any published security advisories