Security fixes are applied to the latest release on npm (tidypress) and to main when a fix is ready. Older tagged releases may not receive backports unless noted in release notes.
Please do not open a public GitHub issue for security vulnerabilities.
Report security issues privately so we can investigate and release a fix before details are public:
- Open a private security advisory on GitHub: Report a vulnerability
- Or email the repository owner via the contact on their GitHub profile if you cannot use advisories.
Include:
- Description of the issue and impact
- Steps to reproduce
- Affected versions or commits
- Any suggested fix (optional)
We aim to acknowledge reports within a few business days and will coordinate disclosure timing with you.
We appreciate responsible disclosure and will not pursue legal action against researchers who follow this policy in good faith.