Please do not report security vulnerabilities in public GitHub issues.
If you discover a vulnerability in this repository or one of its published npm packages, please use GitHub's private vulnerability reporting feature for this repository.
Please include:
- a description of the issue and its potential impact
- the affected package(s) and version(s)
- steps to reproduce, proof of concept, or a minimal test case
- any relevant environment details such as Node.js, TypeDoc, and OS versions
- whether you believe the issue is already being exploited in the wild
You can expect an initial response as soon as practical. After validation, a fix will be prepared and released in a supported version before public disclosure where possible.
Security updates are provided for the latest published major versions of packages in this repository. Older versions should be considered unsupported.
This policy applies to the source code in this repository and the npm packages published from it.