Skip to content

Security: starter-series/npm-package-starter

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly:

  1. Do NOT open a public issue.
  2. Email heznpc@gmail.com or use GitHub Security Advisories.
  3. Include steps to reproduce, impact assessment, and suggested fix if possible.

This is a single-maintainer open-source template. Reports are acknowledged on a best-effort basis as time allows — no SLA. Critical issues affecting the publish pipeline (e.g., CD workflow compromise) are prioritized. For routine dependency advisories, prefer Dependabot.

Security Features

This template includes automated security checks in CI:

  • Dependency auditnpm audit on every push (HIGH/CRITICAL threshold)
  • Secret leak detectiongitleaks scans every commit
  • Dependency updatesDependabot monitors for vulnerable dependencies
  • OIDC trusted publishing — No long-lived secrets needed for npm publish
  • Provenance attestation — Verifiable supply chain built in

Best Practices

  • Never commit .env files or secrets — they are gitignored by default
  • Use GitHub Secrets for deployment credentials
  • Keep dependencies up to date by merging Dependabot PRs

There aren't any published security advisories