Please don't report security problems in public issues, discussions or pull requests.
Report them privately through GitHub: Report a vulnerability. Only the maintainers can see the report.
Please include:
- the package and version affected
- what an attacker can do, and what they need first
- steps or code to reproduce it
- We acknowledge the report within 3 business days.
- We send a first assessment, with severity and next steps, within 10 business days.
- We fix confirmed issues in the latest version of each affected package, publish a GitHub security advisory, and request a CVE where one applies.
- We credit you in the advisory unless you'd rather we didn't.
Please give us a reasonable time to release a fix before you disclose the issue publicly. We aim to fix critical issues within 30 days.
Only the latest published version of each package gets security fixes. Packages are 0.x: breaking changes come in minor versions, and older lines aren't patched.
In scope: the code in this repository and the packages published from it.
Out of scope here: FlyCommerce's hosted services (the dashboard, stores, the APIs). Report those through the same link, and we'll route them to the right team.
Preview builds under the next tag are published by a maintainer from their machine, without provenance, while the app platform is in testing. From the first stable release:
- They're published from GitHub Actions with npm Trusted Publishing and provenance, so no long-lived npm token exists.
- Every release needs a maintainer's approval in the
releaseenvironment. - Their only runtime dependency is each other:
app-serverandapp-emulatoruseapp-bridge.
Already true today: every GitHub Action is pinned to a full commit SHA, and Dependabot keeps them and the dev dependencies current.
Once a package is published, check that what you installed was built from this repository:
npm audit signatures