Skip to content

Security: juicyjusung/nr

SECURITY.md

Security Policy

Supported versions

Security fixes are provided for the latest released version of nr. Before reporting a vulnerability, verify whether it is reproducible with the most recent release.

Report a vulnerability

Use GitHub's private vulnerability reporting to report a suspected vulnerability. Do not disclose it in a public issue, pull request, discussion, or social post.

Include enough information to reproduce and assess the issue:

  • the affected nr version and operating system;
  • the package manager and project or workspace layout involved;
  • reproduction steps or a minimal proof of concept;
  • the expected and observed security impact; and
  • any mitigations you have already identified.

Remove credentials, environment-variable values, private package contents, and unrelated personal data. If sensitive test data is essential to reproduce the issue, explain that in the private report before sharing it.

Please allow maintainers to investigate and coordinate a fix before public disclosure. Security fixes and advisories will be published through this repository when appropriate.

There aren't any published security advisories