Skip to content

Security: rightxt/tracker

.github/SECURITY.md

Security Policy

Supported versions

Security fixes target the latest released version of Tracker. Older versions may not receive backports.

Reporting a vulnerability

Do not report suspected vulnerabilities through public issues, discussions, or pull requests.

Use GitHub's private vulnerability reporting for this repository:

https://github.com/rightxt/tracker/security/advisories/new

Include, when possible:

  • the affected Tracker package, site component, or repository workflow;
  • the affected version or commit;
  • reproduction steps or a proof of concept;
  • the expected security impact;
  • relevant environment details.

Keep exploit details private until the issue has been investigated and any necessary fix has been coordinated.

Scope

Reports may cover runtime code, the site, packaging, supply-chain risks, or repository automation. Relevant examples include:

  • Tracker packages and their public browser/runtime behavior;
  • the project website, demos, and tools when they create a security impact;
  • package contents, exports, installation, or dependency behavior;
  • npm publication, provenance, dependency confusion, or other supply-chain risks;
  • repository automation or release infrastructure that could affect published artifacts or project integrity.

Use issues or Discussions for non-security bugs, feature requests, and usage questions.

There aren't any published security advisories