Skip to content

Security: markcoleman/christmas-fun

SECURITY.md

Security Policy

Thank you for helping keep the Christmas Fun project and its users safe!

Supported Versions

Below is a table indicating which versions are currently supported with security updates:

Version Supported?
2.x (current)
1.x ❌ (no longer supported)
  • 2.x: Actively maintained and patched for security issues.
  • 1.x: No longer receives security or maintenance updates.

Reporting a Vulnerability

If you discover a security vulnerability, please do not create a public issue. Instead, reach out confidentially to the maintainer(s):

Please include as many details as possible, such as:

  • Steps to reproduce the vulnerability (if known)
  • Potential impact
  • Any recommended or suggested fix

Response Time

  • We aim to acknowledge your report within 2 business days.
  • We’ll investigate promptly. If the vulnerability is confirmed, we’ll either:
    • Provide a planned fix timeline, or
    • Issue a hotfix release if it’s critical.

Disclosure

We’ll coordinate with you on a responsible disclosure timeline. Typically, we:

  1. Verify and fix the issue.
  2. Release a patched version.
  3. Publicly disclose (with your credit, if desired) after the fix is available.

Thank You

Your efforts in responsibly disclosing vulnerabilities help ensure the project and its community remain secure and festive. We appreciate your support!

There aren’t any published security advisories